Remote Audits Are Here to Stay, But Are They Appropriate for Every Audit?
- Pierre Venter
- Jul 6
- 4 min read

ISO 19011 – Remote Audits Are Here to Stay, But Are They Appropriate for Every Audit?
By ISO Office (Pty) Ltd
The latest revision of ISO 19011 – Guidelines for Auditing Management Systems continues to recognise remote auditing as an accepted auditing methodology. This reflects the reality that modern organisations increasingly operate across multiple geographical locations, utilise cloud-based management systems, and maintain digital records that can be reviewed without travelling to every site.
However, one important principle should never be overlooked:
Just because an audit can be conducted remotely does not necessarily mean it should be.
The decision to perform a remote audit, an on-site audit, or a combination of both should always be based on risk, complexity, and the ability to obtain sufficient objective evidence.
For internal auditors responsible for multiple facilities, this is perhaps one of the most important planning decisions before the audit programme even begins.
Remote Auditing Is a Method – Not an Objective
The purpose of any internal audit remains unchanged.
The auditor must still determine whether the management system:
conforms to the organisation’s own requirements;
conforms to applicable ISO standard requirements;
is effectively implemented;
is maintained; and
is capable of achieving its intended outcomes.
Whether the audit is conducted in person or remotely should never compromise these objectives.
Remote auditing simply provides another method for gathering objective evidence.
Understanding the Risks Before Selecting a Remote Audit
ISO 19011 promotes a risk-based approach when planning audits.
Before deciding to conduct a remote audit, auditors should evaluate several questions.
1. What Is the Nature of the Organisation?
Some organisations are predominantly administrative.
Examples include:
Consulting companies
Financial institutions
Software developers
Insurance companies
Design offices
Professional service providers
These organisations generate most of their evidence electronically.
Procedures, records, approvals, objectives, management reviews, and performance data are generally stored within digital systems.
Remote auditing can therefore be highly effective.
Conversely, organisations whose activities rely heavily on physical operations present greater auditing challenges.
Examples include:
Mining operations
Manufacturing plants
Engineering workshops
Construction sites
Warehousing operations
Chemical processing facilities
Transport and logistics operations
Food manufacturing
Utilities and infrastructure projects
In these environments, significant objective evidence can only be obtained by physically observing operations.
2. Consider the Scope of the Audit
The audit scope should heavily influence the audit method.
For example:
A Remote Audit May Be Appropriate For:
Management Review
Document Control
Training Records
Competency Records
Risk Registers
Objectives and KPI monitoring
Internal Audit Programme
Corrective Actions
Supplier Evaluations
Legal Registers
Calibration Records (verification of records)
Most of these activities involve reviewing documented information.
On-Site Verification Is Often Essential For:
Production activities
Mining operations
Plant inspections
Warehouse activities
Vehicle inspections
Operational controls
Environmental controls
Housekeeping
PPE compliance
Behavioural safety observations
Emergency preparedness
Equipment maintenance
Process verification
Product identification and traceability
These require observation, discussion with personnel, and verification of actual practices.
No camera or Teams meeting can fully replace walking through an operation.
3. Consider Process Complexity
One of the biggest mistakes auditors make is assuming every process carries equal audit risk.
This is seldom true.
Consider the following example.
Process | Complexity | Recommended Audit Method |
Document Control | Low | Remote |
HR & Competence | Low | Remote |
Procurement | Medium | Remote or Hybrid |
Maintenance | Medium | Hybrid |
Production | High | Primarily On-site |
Mining Operations | Very High | On-site with Remote Preparation |
Laboratory Testing | High | Hybrid |
Emergency Preparedness | High | On-site |
The greater the operational complexity, the greater the need for physical verification.
A Practical Hybrid Audit Approach
Rather than choosing between remote and on-site auditing, many organisations will obtain the best results by combining both.
This allows administrative activities to be completed remotely while maximising valuable on-site time for operational verification.
For example:
Example 1 – Manufacturing Company (5-Day Internal Audit)
Desktop Audit (2 Days)
Review:
Procedures
Objectives
Risk Registers
Training Records
Supplier Evaluations
Previous Nonconformities
Calibration Records
Management Review Minutes
On-site Audit (3 Days)
Verify:
Production
Maintenance
Warehouse
Incoming Inspection
Dispatch
Housekeeping
PPE
Operational Controls
Employee Interviews
This reduces travel costs while ensuring operational activities receive appropriate attention.
Example 2 – Mining Contractor (6-Day Internal Audit)
Desktop Audit (2 Days)
Review:
SHEQ Documentation
Risk Assessments
Training Records
Legal Compliance
Incident Investigations
Equipment Registers
Maintenance Planning
Corrective Actions
On-site Audit (4 Days)
Verify:
Mining activities
Workshops
Conveyor systems
Heavy equipment
Explosive controls (where applicable)
Contractor management
Environmental controls
Behaviour-based observations
Emergency response readiness
In this scenario, approximately two-thirds of the audit should be conducted on-site due to the inherent operational risks.
Example 3 – Multi-Site Retail Organisation (10 Branches)
Instead of travelling to every branch for five days each, the auditor could adopt a risk-based approach.
Desktop activities:
Review documentation centrally.
Analyse branch performance data.
Evaluate KPIs.
Review complaints.
Assess previous audit findings.
Then conduct on-site audits at selected branches based on:
Highest operational risk
Poor previous performance
New facilities
Recent incidents
Significant organisational changes
Branches demonstrating consistent performance may require shorter verification visits than higher-risk locations.
Developing a Risk-Based Hybrid Audit Matrix
A useful planning method is to score each auditable process against a set of risk factors, such as:
Process complexity
Health and safety risk
Environmental impact
Regulatory requirements
Previous audit findings
Process maturity
Frequency of change
Reliance on physical observation
Competence of personnel
Customer impact
Processes with low overall risk can receive a greater proportion of desktop auditing, while higher-risk processes should receive more on-site audit time.
This structured approach supports consistency, transparency, and effective use of audit resources across multiple sites.
The Biggest Risk of Remote Auditing
Perhaps the greatest limitation of remote auditing is that auditors may unintentionally become document reviewers rather than management system auditors.
Documents only demonstrate what an organisation says it does.
A management system audit must also determine:
What actually happens?
Do employees understand the process?
Are procedures consistently followed?
Are operational controls effective?
Is the management system delivering its intended outcomes?
These questions often require direct observation and interaction with people performing the work.
Final Thoughts
Remote auditing has become a valuable addition to the auditor’s toolbox and is now recognised within ISO 19011 as a legitimate auditing approach. However, its success depends on thoughtful planning and the application of risk-based thinking.
For internal auditors managing multiple sites, the most effective solution will often be a hybrid audit, combining desktop reviews of documented information with targeted on-site verification of higher-risk and more complex operational processes.
Rather than asking, “Can this audit be conducted remotely?”, a better question is:
“What audit method will provide sufficient, reliable, and appropriate objective evidence to determine whether the management system is both conforming and effective?”

That question lies at the heart of every successful audit.




Comments