Why ISO 19011:2026 Pays More Attention to Second Party Audits
If you conduct supplier audits, you have probably noticed that the previous edition of ISO 19011 treated second party audits as something of an afterthought. The 2018 edition acknowledged they existed and noted that the guidance applied to them, but it did not give supply chain auditing the dedicated attention it deserved. The 2026 revision changes that. Second party audits now receive more specific, practical guidance throughout the standard, reflecting how central supplier oversight has become to modern management systems.
On this page
This matters because supply chain risk is no longer a niche concern. Organisations across every sector are under pressure to demonstrate that their suppliers meet defined requirements, whether those requirements come from ISO 9001 Clause 8.4, customer contracts, regulatory obligations, or their own risk management frameworks. The auditors tasked with that work need more than generic audit guidance. ISO 19011:2026 begins to fill that gap.
This article walks through what has changed, what the new guidance actually says, and how to apply it in practice when you are planning and conducting second party audits.
What Is a Second Party Audit and Where Does It Sit?
Before getting into the changes, it is worth being precise about terminology. A second party audit is conducted by, or on behalf of, an organisation on its suppliers or other external parties. The auditing organisation has a direct interest in the outcome because it relies on those suppliers to deliver products, services, or processes that affect its own operations or customers.
This distinguishes second party audits from first party audits, which are internal audits conducted within your own organisation, and third party audits, which are independent certification or regulatory audits conducted by accredited bodies. If you want a clear comparison of these audit types, our article on second party vs third party audits covers the distinctions in detail.
Second party audits sit in a space that is simultaneously more flexible and more complex than the other two types. You have a commercial relationship with the auditee. You may have contractual leverage, or you may not. The auditee may be cooperative, or they may view your audit as an intrusion. The audit objectives are set by your organisation, not by an accreditation body. All of this creates challenges that generic audit guidance does not fully address.
Exemplar Global Recognised Training ProviderRTP No. 310970What ISO 19011:2026 Added for Second Party Auditing
Clearer Scope Language That Includes Supply Chains
The 2026 edition updates the scope clause to make explicit that the guidelines apply to second party audits, including supplier and supply chain audits. This is not just cosmetic. It signals that the standard is intended to serve supply chain auditors as a genuine reference, not just as background reading.
The scope also acknowledges that second party audits can take different forms, from a full on site assessment of a critical supplier to a remote document review of a lower risk vendor. This flexibility is important. Not every supplier warrants the same level of scrutiny, and the standard now better supports a risk based approach to deciding what kind of audit is appropriate.
Audit Programme Guidance That Accounts for Supplier Risk
Clause 5 of ISO 19011:2026, which covers the management of an audit programme, now includes more explicit guidance on how to factor supplier risk into programme planning. This is a practical improvement. When you are managing a second party audit programme across dozens or hundreds of suppliers, you need a defensible rationale for why you audit some suppliers annually, others every three years, and some only by desk review.
The updated guidance supports using risk criteria such as the criticality of the supplied product or service, the supplier's performance history, the maturity of the supplier's management system, and the consequences of supplier failure for your own operations or customers. These factors should drive both the frequency and depth of your supplier audits.
For those building or updating a supplier audit programme, this aligns well with the requirements of ISO 9001 Clause 8.4, which requires organisations to determine the type and extent of controls applied to external providers based on the potential impact on the organisation's ability to meet customer requirements. The 19011 guidance now gives you a clearer methodology for making those determinations.
Audit Objectives Tailored to the Supply Chain Context
One of the more useful additions in the 2026 edition is guidance on setting audit objectives that are specific to the second party context. Generic audit objectives like “assess conformance with requirements” are not particularly useful when you are auditing a supplier. You need to be clear about what you are actually trying to find out.
ISO 19011:2026 encourages second party auditors to define objectives that address questions such as: Does this supplier have the capability to consistently deliver what we need? Are there systemic weaknesses in their processes that could affect our supply? Do they understand and apply our specific requirements? Are there emerging risks in their operations that we should be tracking?
These are different questions from those you would ask in an internal audit or a certification audit, and they require a different audit approach. The standard now acknowledges this explicitly, which helps auditors justify a more targeted and commercially grounded audit scope.
Competence Requirements for Supply Chain Auditors
Clause 7 of ISO 19011:2026 deals with auditor competence. The 2026 edition adds more nuance around the competence required for second party audits specifically. Auditing a supplier is not the same as auditing your own organisation. You need to understand the supplier's industry and processes, the contractual and commercial context of the relationship, and how to gather evidence in an environment where you have limited authority and may face resistance.
The standard now recognises that second party auditors may need sector specific technical knowledge that goes beyond general auditing competence. If you are auditing a precision machining supplier, you need to understand tolerances, inspection methods, and traceability requirements. If you are auditing a software development supplier, you need to understand version control, testing practices, and change management. Generic auditing skills are necessary but not sufficient.
This has practical implications for how organisations select and train their supplier auditors. It is not enough to send someone who has completed a lead auditor course and call it done. They also need the technical background to assess whether what they are seeing in the supplier's facility actually represents good practice.
Handling Conflicts of Interest in the Supply Chain Context
The 2026 edition gives more attention to managing conflicts of interest in second party audits. This is a genuinely tricky area. The auditing organisation has a commercial relationship with the auditee. There may be pressure, explicit or implicit, to reach a favourable conclusion. The auditor may be someone who also negotiates with the supplier or manages the commercial relationship.
ISO 19011:2026 reinforces the principle of impartiality and notes that second party auditors need to be aware of the particular pressures that arise in supply chain relationships. The guidance encourages organisations to think carefully about who conducts supplier audits and whether those individuals can genuinely maintain independence from the commercial relationship.
In practice, this often means separating the audit function from the procurement and commercial function. The person who negotiates contracts with a supplier should generally not be the person who audits them. Where that separation is not possible, organisations should at least document how they have managed potential conflicts.
Practical Implications for Your Supplier Audit Programme
Segmenting Your Supplier Base by Risk
The first practical step is to segment your suppliers by risk. Not all suppliers need the same level of audit attention. A supplier providing generic office consumables poses a very different risk profile from a supplier providing a critical safety component or managing a process that is outsourced from your own quality management system.
A useful starting point is to classify suppliers across two dimensions: the criticality of what they supply, and the confidence you have in their management system. High criticality combined with low confidence means a full on site audit. High criticality with high confidence might mean a targeted audit focusing on specific risk areas. Low criticality suppliers might be managed through performance monitoring and periodic desk reviews rather than on site audits at all.
This kind of segmentation gives you a defensible audit programme that is proportionate to risk, which is exactly what ISO 19011:2026 now more explicitly supports. It also helps you make the case internally for why you are spending audit resources on certain suppliers and not others.
Setting Meaningful Audit Objectives Before You Arrive
One of the most common weaknesses in supplier audits is vague objectives. Auditors show up with a generic checklist and work through it without a clear sense of what they are actually trying to find out. The result is an audit that covers a lot of ground superficially but misses the specific risks that matter for that supplier relationship.
Before you plan a supplier audit, ask yourself what you most need to know about this supplier right now. Are you concerned about their capacity to meet increased demand? Do you have quality data suggesting a process is drifting? Are you about to extend their contract and want to verify their claims about their management system? Are there new regulatory requirements that they need to be meeting?
The answers to these questions should drive your audit objectives, which in turn drive your audit criteria, your sampling strategy, and the questions you ask. An audit with clear, specific objectives is almost always more useful than one conducted to a generic template. Our article on how to write audit objectives that actually focus your audit covers this process in detail.
Adapting Your Evidence Gathering Approach
Gathering evidence in a supplier audit is different from gathering evidence in an internal audit. You have less familiarity with the environment, less authority to demand access, and less ability to follow up easily if something is unclear. You need to be efficient and targeted.
Prepare thoroughly before you arrive. Review any previous audit reports, supplier performance data, customer complaints that traced back to this supplier, and any documented information the supplier has shared. Identify the specific processes and records you want to sample. Plan your interviews in advance so you are not wasting time on site working out who to talk to.
On site, focus on the processes that are most relevant to your audit objectives. Do not let the supplier guide you only to the areas they are comfortable showing you. A well prepared auditor arrives with a clear plan and politely but firmly follows it. Be direct about what you need to see and why.
Reporting Findings in a Way That Drives Improvement
Supplier audit reports serve a different purpose from internal audit reports. They need to communicate clearly to both your own organisation and, in most cases, the supplier. They need to be specific enough that the supplier understands exactly what the finding is and what is expected of them, but also professional enough to preserve the commercial relationship.
Avoid vague language. “The supplier's document control could be improved” is not a useful finding. “The supplier's current revision of the product specification (Rev C) was not available at the point of use in the machining area. Operators were using Rev B, which does not reflect the tolerance change implemented in March” is a finding that can actually be acted on.
Be clear about what you expect in response. Specify whether you require a corrective action, a root cause analysis, or simply an acknowledgement. Set a timeframe. And follow up. A supplier audit that produces findings which are never verified is largely a waste of time. Our post on supplier audit follow up covers how to make findings stick.
Remote Supplier Audits and ISO 19011:2026
The 2026 edition also gives more attention to remote auditing as a legitimate approach for second party audits. This is a practical acknowledgment of how supplier auditing has evolved since 2020. Remote audits are now a standard tool in the supplier auditor's kit, not an emergency workaround.
For lower risk suppliers, or for specific elements of a supplier audit such as document review, records sampling, or interviews with management, remote methods can be entirely appropriate. The standard now provides clearer guidance on when remote approaches are suitable and what additional considerations apply, including data security, technology reliability, and the limitations on physical observation.
The key question for any remote supplier audit is whether the evidence you can gather remotely is sufficient to support your audit conclusions. For some audit objectives, remote methods work well. For others, particularly those involving physical processes, production environments, or workplace conditions, on site presence is difficult to replace. Be honest about this in your audit planning and do not default to remote simply because it is cheaper or more convenient.
Building Second Party Auditing Competence
If your role involves conducting supplier audits, or if you manage a team that does, the updates in ISO 19011:2026 are a useful prompt to review the competence of your auditors. The standard now more explicitly recognises that second party auditing requires a specific skill set that goes beyond general audit training.
At a minimum, your supplier auditors should have formal audit training, relevant technical knowledge for the sectors they audit, and experience conducting audits in environments where they do not have home ground advantage. They should also understand the commercial and contractual context of the supplier relationships they are auditing, so they can interpret what they find in the right context.
If you are looking to build or formalise your supplier auditing capability, a lead auditor qualification gives you the audit methodology foundation you need. From there, sector specific technical knowledge and supervised audit experience complete the picture. Our article on the ISO auditor career path from internal auditor to lead auditor explains how that progression typically works.
Exemplar Global Recognised Training ProviderRTP No. 310970What This Means for Organisations Being Audited by Their Customers
It is worth briefly considering the other side of the equation. If your organisation is subject to second party audits from your customers, the changes in ISO 19011:2026 have implications for you too. Your customers' auditors are now working from guidance that encourages more targeted, risk based, and evidence driven audits. They are more likely to arrive with specific objectives and focused sampling plans rather than working through a generic checklist.
This means the best way to prepare for a customer audit is to understand what risks your customer is most concerned about in your relationship with them. Review your own performance data, your nonconformity history, and any issues that have arisen in your supply of products or services. Make sure your documented information is current and accessible. And be prepared to demonstrate, not just describe, how your processes work.
A well run management system is still the best preparation for any audit. But understanding the approach your customer's auditor is likely to take helps you anticipate where they will focus and make sure you can respond clearly and confidently.
Audit Workshop Training for Supply Chain Auditors
At Audit Workshop, our lead auditor courses are built around real audit practice, not theory. Dilawar Laghari has conducted over 500 external ISO certification audits across Australia, the Middle East, and South Asia, and that experience shapes how we teach auditing, including the specific challenges of second party and supplier audits.
If you are building your supplier auditing capability, our ISO 9001 Lead Auditor course covers the audit methodology you need, including how to plan targeted audits, gather evidence in unfamiliar environments, and write findings that hold up to scrutiny. We also offer training across ISO 14001, ISO 45001, ISO 27001, and other standards for auditors working across different supply chain contexts.
Our courses are available as live virtual sessions and self paced options, so you can fit training around your work commitments. Visit auditworkshop.com to explore what is available and find the right course for where you are in your auditing career.













