ISO 19011
Guidelines for auditing management systems
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (8)
Audit Principles
| Code | Title |
|---|---|
| 4.a | Integrity Principle |
| 4.b | Fair Presentation |
| 4.c | Due Professional Care |
| 4.d | Confidentiality |
| 4.e | Independence |
| 4.f | Evidence-Based Approach |
| 4.g | Risk-Based Approach |
Audit Process
| Code | Title |
|---|---|
| 6.2 | Approach selection |
| 6.3 | Information security awareness, education and training |
| 6.4 | Logging and Monitoring |
| 6.5 | Preparing and Distributing Audit Report |
| 6.6 | Confidentiality or non-disclosure agreements |
| 6.7 | Conducting Audit Follow-up |
Audit Programme
| Code | Title |
|---|---|
| 5.2 | Token Management |
| 5.3 | Determining and Evaluating Audit Programme Risks |
| 5.4 | Establishing Audit Programme |
| 5.5 | Implementing Audit Programme |
| 5.6 | Monitoring Audit Programme |
| 5.7 | Threat intelligence |
Auditor Competence
| Code | Title |
|---|---|
| 7.2 | Security Training and Awareness |
| 7.3 | Risk evaluation |
| 7.4 | Asset valuation |
| 7.5 | Threat assessment |
| 7.6 | Vulnerability assessment |
ISO 19011: Improvement
Continual improvement of quality management system (ISO 19011)
| Code | Title |
|---|---|
| ISO19011-16 | Continual improvement methodology |
| ISO19011-17 | Corrective and preventive actions |
| ISO19011-18 | Innovation and change management |
ISO 19011: Leadership & Planning
Quality management leadership and planning (ISO 19011)
| Code | Title |
|---|---|
| ISO19011-01 | Quality policy and objectives |
| ISO19011-02 | Leadership commitment to quality |
| ISO19011-03 | Risk-based thinking and planning |
| ISO19011-04 | Resource management for quality |
| ISO19011-05 | Organizational roles and responsibilities |
ISO 19011: Operational Controls
Quality controls in operations (ISO 19011)
| Code | Title |
|---|---|
| ISO19011-06 | Operational planning and control |
| ISO19011-07 | Requirements for products and services |
| ISO19011-08 | Design and development controls |
| ISO19011-09 | Control of externally provided processes |
| ISO19011-10 | Production and service provision controls |
ISO 19011: Performance Evaluation
Measuring and evaluating quality performance (ISO 19011)
| Code | Title |
|---|---|
| ISO19011-11 | Monitoring, measurement, and analysis |
| ISO19011-12 | Internal audit program |
| ISO19011-13 | Management review process |
| ISO19011-14 | Customer satisfaction measurement |
| ISO19011-15 | Nonconformity and corrective action |
Your Compliance Coverage
If you comply with ISO 19011, you already cover:
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
17%
7 controls mapped
Compare →SWIFT CSCF
14%
6 controls mapped
Compare →ISO 15189:2022 - Medical Laboratories Requirements for Quality and Competence
14%
6 controls mapped
Compare →+ 432 more: ISO 20000-1 (14%), NIST SP 800-144 (14%)
See all 435 mapped frameworks ↓Maps to 435 other frameworks
Frequently Asked Questions
What is ISO 19011?
ISO 19011 is a compliance framework from International with 8 domains and 42 controls. Guidelines for auditing management systems It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ISO 19011 have?
ISO 19011 has 42 controls organised across 8 domains. The largest domains are Audit Principles (7 controls), Audit Process (6 controls), Audit Programme (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ISO 19011 map to?
ISO 19011 maps to 435 other compliance frameworks. The top mapping partners are NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements (17% coverage), SWIFT CSCF (14% coverage), ISO 15189:2022 - Medical Laboratories Requirements for Quality and Competence (14% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ISO 19011 compliance?
Start your ISO 19011 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 19011 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 42 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required