
ISO 19011:2026 Guidelines for Auditing Management Systems - Annex A, Clauses 7-12
Welcome back to the ISO Review Podcast, your trusted source for the latest in international standards development and management systems excellence. In this episode, Jim and Howard continue their practical deep dive into ISO 19011, specifically focusing on Appendix A. Together, they explore key auditing topics such as compliance and conformance, understanding organizational context, leadership and commitment, managing risks and opportunities, lifecycle perspectives, and effective auditing of the supply chain. With insights drawn from decades of ISO experience, Jim shares real-world strategies for making audits meaningful, maintaining compliance, and enhancing the value of your management system. Whether you’re an auditor, manager, or simply passionate about process improvement, this episode is packed with actionable guidance to help you get the most out of your internal audits. DISCUSSION 1. Main Topic Introduction: ISO 19011 Appendix A Howard Fox introduces ISO 19011 Appendix A as the focus of the episode 04:41 2. Overview of ISO 19011 and Annex A Jim Moran clarifies ISO 19011 is an auditing guidance standard, not a requirement 04:52 Explanation of previously covered topics in Annex A, including: Audit preparation Audit methods Process, judgment, performance, verifying information, sampling 3. New Annex A Topics for this Episode a. Auditing Compliance within a Management System 05:43 Difference between compliance (legal) and conformance (voluntary standards) Importance of using correct terminology in documentation Companies must identify applicable statutory and regulatory requirements 07:15 Auditing process flow to connect compliance requirements to activities Need for mechanisms to track changes in requirements Documentation and processes to maintain compliance Sector-specific challenges (quality, environmental, health/safety, information security) Interviewing compliance-responsible personnel as part of audit b. Auditing Context (A.8) 12:29 Aligning audits with the organization's context and standards Regulatory bodies as interested parties Importance of planned compliance rather than hope Elements auditors should examine: Verifiable evidence Suitability and competence Audit focus on results, risk management, and opportunities for improvement c. Auditing Leadership and Commitment (A.9) 14:57 Leadership requirements in harmonized ISO standards (especially Clause 5.1) New requirements in latest ISO 9001 FDIS: mandate to develop a "quality culture" Auditing for evidence of leadership’s accountability and management system effectiveness Role of auditors in interacting with top management and assessing their commitment Interviewing personnel to assess perception of management’s commitment d. Auditing Risks and Opportunities (A.10) 18:05 Importance of robust risk identification by the organization Reference to ISO 31000 steps: Identify, Analyze, Assess risks 18:51 Use of a risk mitigation plan if risks are high Inquiry into risk management practices at activity level Role of top management in addressing unmanaged risks and allocating resources Considering internal and external sources of risk Visual aids (e.g. symbols) for indicating risk types in process flows e. Lifecycle Perspective (A.11) 22:06 Requirement for some management systems (notably environmental) to apply a lifecycle perspective Considering influence and control over a product/service lifecycle Examples and practical steps: using AI or web for visual lifecycle diagrams Applications in environmental management, climate impact, and improving performance f. Auditing the Supply Chain (A.12) 25:24 Increased awareness of global supply chain complexity post-COVID Mention of ISO 27003 Part 2 for information security in supply chains Types of supply chain audits: Management system Process Product Information security configuration Explanation of first, second, and third-party audits Contract-focused auditing for practicality and audit scope management Ongoing surveillance and continual improvement audits Relationship between supply chain, lifecycle, and risk management 7. Importance of ISO Standard Appendices Howard Fox and Jim Moran discuss the value of appendix content in ISO standards 31:45 Suggestion to use AI for sourcing additional material to enhance audit value 8. Resources and Closing Jim Moran gives details about Simplify ISO, their software, and additional resources (IMSIpro.org, LinkedIn, YouTube) 32:40 Howard Fox mentions where to find more information about himself and closing statements 35:16 Farewells and sign-off 34:53 NEXT STEPS We appreciate your likes & comments, and shares. Click here to visit the SimplifyISO website. Click here to visit the International Management System Institute website and learn how to become a Certified ISO Management System Professional. Click here to learn about our new DIY ISO 9001 program using AI Learn more about Jim on LinkedIn & YouTube. LinkedIn LinkedIn Articles YouTube Learn about Howard's Coaching and Podcast Services Website : https://foxcoaching.com LinkedIn : https://www.linkedin.com/in/foxcoachinginc/ Podcast Discovery Call: https://calendly.com/foxcoachinginc/podcast-discovery-call KEYWORDS Jim Moran, Information Security Management System, ISO 19011:2026, ISO Review Podcast, SimplifyISO, Podcast #JimMoran #InformationSecurityManagementSystem #ISO9011:2026 #ISOReviewPodcast #SimplifyISO #Podcast















