Welcome back to the ISO Review Podcast, your trusted source for the latest developments in international standards and practical ISO management system insights. In this episode, Jim and Howard conclude their comprehensive review of ISO 19011:2026, the essential auditing guidelines for management systems. Together, they dive into Annex A, covering Clauses A.13 to A.18, and discuss critical topics like working documents for combined audits, collecting and verifying digital evidence, onsite and remote auditing methods, and best practices for reporting findings—especially when audits span multiple standards. Drawing from real-world examples and decades of experience, Jim also offers tips for holistic audits, efficient document control, and navigating today’s virtual audit landscape. Stay tuned for expert advice, practical anecdotes, and a glimpse at what’s next: a preview of changes coming in ISO 9001:2026. DISCUSSION 1. Overview of Current and Upcoming Standards Announcement: Completion of ISO 19011:2026 coverage (01:40)Recap: Previous episode covered up to Annex A.12Plan for this episode: Covering Annex A.13 to A.18Teaser: Upcoming release of ISO 9001:2026 and plan to discuss it in the next episode (02:14)2. Introduction to Annex A.13–A.18 in ISO 19011:2026 Reminder of the prevalence of integrated/multi-standard auditsExample: Client with ISO 9001, 14001, 45001, and 27001 across multiple sitesImpact of COVID-19 on auditing practices (shift to virtual audits)Introduction of virtual audit adaptations (03:06 - 04:16)3. Clause A.13: Working Documents for Combined Audits Importance of preparing audit criteria and working documentsCore elements of an audit plan: objective, scope, criteriaDifferent audit types (surveillance, internal, registration, Stage 1)Use of checklists and evidence collectionChallenges and efficiencies in auditing multiple standards simultaneously (05:06)4. Efficient Document Management Across Systems Leverage harmonized structure (clauses 4, 5, 6, 7, 9, 10 common across standards)Unique aspects in Clause 8 for specific domains (quality, environmental, etc.)Efficient review and avoidance of duplication through integrated documentation and software solutionsImportance of auditors’ authority and access to necessary documents (07:19 - 09:46)5. Clause A.14: Collecting and Verifying Digital Evidence Verification of authenticity and integrity (versioning, access logs, etc.)Sampling plan considerations for electronic dataHandling of digital evidence: screenshots, document identification, and data disposalGuidance on documenting evidence without unnecessary data storage (09:47 - 13:50)6. Clause A.15: Onsite Audit Considerations Health and safety and information security requirements for onsite auditorsExample of auditor pre-entry requirements (training and certification)COVID-19 impacts: masks, vaccination, cultural norms, working hoursAdvance communication: audit plans, objective/scope/criteria, minimal disruptionAddressing the misconception of auditors as "ISO cops"; clarification of audit outcomes (14:54 - 18:16)7. Audit Finding Process and Nonconformity Management Types of findings: opportunities for improvement, nonconformancesCorrective action plans and timelines (routine and urgent safety issues)Legal obligations in reporting severe health and safety violations (18:16 - 20:31)8. Clause A.16: Remote Auditing Methods Expansion of remote auditing due to recent technological and situational changesTechnical requirements: prep, access, protocols, data security, contingency planningRegistrar oversight and accreditation (standards 17011 and 17012)Practical matters: breaks, muting, permissions for screen captures and recordingsAuditor competence with remote tools (Teams, Zoom, WebEx, etc.) (20:32 - 23:05)9. Clause A.17: Remote Interviews Adapting questioning for remote interviewsUse of real-time screen sharing or physical walkthroughs via devicesEnsuring evidence gathered is verifiable and objectiveAppropriate documentation language (avoiding subjective/accusatory statements)Identifying process improvement opportunities and documentation mismatches (23:27 - 27:18)10. Clause A.18: Audit Findings and Reporting Across Multiple Standards Approaches for findings that touch multiple standards: separate or combined reportingAdvantages of harmonized structure/high-level structure in auditsProviding a holistic view for the auditee about their integrated management system’s performance (27:18 - 29:51)12. Episode Wrap-Up and Next Steps Summary: Completion of ISO 19011:2026 reviewNext episode: Review of ISO 9001:2026Listeners guided on where to find more resources (SimplifyISO.com, IMSIPRO.org, LinkedIn, YouTube, Fox Coaching)Farewell and reminders about show notes/backlinks (29:51 - 32:48)NEXT STEPS We appreciate your likes & comments, and shares. Click here to visit the SimplifyISO website. Click here to visit the International Management System Institute website and learn how to become a Certified ISO Management System Professional. Click here to learn about our new DIY ISO 9001 program using AI Learn more about Jim on LinkedIn & YouTube. LinkedIn LinkedIn Articles YouTube Learn about Howard's Coaching and Podcast Services Website: https://foxcoaching.com LinkedIn: https://www.linkedin.com/in/foxcoachinginc/ Podcast Discovery Call: https://calendly.com/foxcoachinginc/podcast-discovery-call KEYWORDS Jim Moran, Information Security Management System, ISO 19011:2026, ISO Review Podcast, SimplifyISO, Podcast #JimMoran #InformationSecurityManagementSystem #ISO9011:2026 #ISOReviewPodcast #SimplifyISO #Podcast