top of page
Search

Remote Audits Are Here to Stay, But Are They Appropriate for Every Audit?


ISO 19011 – Remote Audits Are Here to Stay, But Are They Appropriate for Every Audit?

By ISO Office (Pty) Ltd


The latest revision of ISO 19011 – Guidelines for Auditing Management Systems continues to recognise remote auditing as an accepted auditing methodology. This reflects the reality that modern organisations increasingly operate across multiple geographical locations, utilise cloud-based management systems, and maintain digital records that can be reviewed without travelling to every site.

However, one important principle should never be overlooked:

Just because an audit can be conducted remotely does not necessarily mean it should be.


The decision to perform a remote audit, an on-site audit, or a combination of both should always be based on risk, complexity, and the ability to obtain sufficient objective evidence.


For internal auditors responsible for multiple facilities, this is perhaps one of the most important planning decisions before the audit programme even begins.



Remote Auditing Is a Method – Not an Objective

The purpose of any internal audit remains unchanged.

The auditor must still determine whether the management system:

  • conforms to the organisation’s own requirements;

  • conforms to applicable ISO standard requirements;

  • is effectively implemented;

  • is maintained; and

  • is capable of achieving its intended outcomes.


Whether the audit is conducted in person or remotely should never compromise these objectives.

Remote auditing simply provides another method for gathering objective evidence.



Understanding the Risks Before Selecting a Remote Audit

ISO 19011 promotes a risk-based approach when planning audits.

Before deciding to conduct a remote audit, auditors should evaluate several questions.


1. What Is the Nature of the Organisation?

Some organisations are predominantly administrative.

Examples include:

  • Consulting companies

  • Financial institutions

  • Software developers

  • Insurance companies

  • Design offices

  • Professional service providers


These organisations generate most of their evidence electronically.

Procedures, records, approvals, objectives, management reviews, and performance data are generally stored within digital systems.

Remote auditing can therefore be highly effective.


Conversely, organisations whose activities rely heavily on physical operations present greater auditing challenges.


Examples include:

  • Mining operations

  • Manufacturing plants

  • Engineering workshops

  • Construction sites

  • Warehousing operations

  • Chemical processing facilities

  • Transport and logistics operations

  • Food manufacturing

  • Utilities and infrastructure projects


In these environments, significant objective evidence can only be obtained by physically observing operations.



2. Consider the Scope of the Audit

The audit scope should heavily influence the audit method.

For example:


A Remote Audit May Be Appropriate For:

  • Management Review

  • Document Control

  • Training Records

  • Competency Records

  • Risk Registers

  • Objectives and KPI monitoring

  • Internal Audit Programme

  • Corrective Actions

  • Supplier Evaluations

  • Legal Registers

  • Calibration Records (verification of records)


Most of these activities involve reviewing documented information.



On-Site Verification Is Often Essential For:

  • Production activities

  • Mining operations

  • Plant inspections

  • Warehouse activities

  • Vehicle inspections

  • Operational controls

  • Environmental controls

  • Housekeeping

  • PPE compliance

  • Behavioural safety observations

  • Emergency preparedness

  • Equipment maintenance

  • Process verification

  • Product identification and traceability


These require observation, discussion with personnel, and verification of actual practices.

No camera or Teams meeting can fully replace walking through an operation.



3. Consider Process Complexity

One of the biggest mistakes auditors make is assuming every process carries equal audit risk.

This is seldom true.

Consider the following example.

Process

Complexity

Recommended Audit Method

Document Control

Low

Remote

HR & Competence

Low

Remote

Procurement

Medium

Remote or Hybrid

Maintenance

Medium

Hybrid

Production

High

Primarily On-site

Mining Operations

Very High

On-site with Remote Preparation

Laboratory Testing

High

Hybrid

Emergency Preparedness

High

On-site

The greater the operational complexity, the greater the need for physical verification.



A Practical Hybrid Audit Approach

Rather than choosing between remote and on-site auditing, many organisations will obtain the best results by combining both.

This allows administrative activities to be completed remotely while maximising valuable on-site time for operational verification.

For example:


Example 1 – Manufacturing Company (5-Day Internal Audit)

Desktop Audit (2 Days)

Review:

  • Procedures

  • Objectives

  • Risk Registers

  • Training Records

  • Supplier Evaluations

  • Previous Nonconformities

  • Calibration Records

  • Management Review Minutes


On-site Audit (3 Days)

Verify:

  • Production

  • Maintenance

  • Warehouse

  • Incoming Inspection

  • Dispatch

  • Housekeeping

  • PPE

  • Operational Controls

  • Employee Interviews


This reduces travel costs while ensuring operational activities receive appropriate attention.



Example 2 – Mining Contractor (6-Day Internal Audit)

Desktop Audit (2 Days)

Review:

  • SHEQ Documentation

  • Risk Assessments

  • Training Records

  • Legal Compliance

  • Incident Investigations

  • Equipment Registers

  • Maintenance Planning

  • Corrective Actions


On-site Audit (4 Days)

Verify:

  • Mining activities

  • Workshops

  • Conveyor systems

  • Heavy equipment

  • Explosive controls (where applicable)

  • Contractor management

  • Environmental controls

  • Behaviour-based observations

  • Emergency response readiness


In this scenario, approximately two-thirds of the audit should be conducted on-site due to the inherent operational risks.



Example 3 – Multi-Site Retail Organisation (10 Branches)

Instead of travelling to every branch for five days each, the auditor could adopt a risk-based approach.

Desktop activities:

  • Review documentation centrally.

  • Analyse branch performance data.

  • Evaluate KPIs.

  • Review complaints.

  • Assess previous audit findings.


Then conduct on-site audits at selected branches based on:

  • Highest operational risk

  • Poor previous performance

  • New facilities

  • Recent incidents

  • Significant organisational changes


Branches demonstrating consistent performance may require shorter verification visits than higher-risk locations.



Developing a Risk-Based Hybrid Audit Matrix

A useful planning method is to score each auditable process against a set of risk factors, such as:

  • Process complexity

  • Health and safety risk

  • Environmental impact

  • Regulatory requirements

  • Previous audit findings

  • Process maturity

  • Frequency of change

  • Reliance on physical observation

  • Competence of personnel

  • Customer impact


Processes with low overall risk can receive a greater proportion of desktop auditing, while higher-risk processes should receive more on-site audit time.

This structured approach supports consistency, transparency, and effective use of audit resources across multiple sites.



The Biggest Risk of Remote Auditing

Perhaps the greatest limitation of remote auditing is that auditors may unintentionally become document reviewers rather than management system auditors.

Documents only demonstrate what an organisation says it does.

A management system audit must also determine:

  • What actually happens?

  • Do employees understand the process?

  • Are procedures consistently followed?

  • Are operational controls effective?

  • Is the management system delivering its intended outcomes?


These questions often require direct observation and interaction with people performing the work.



Final Thoughts

Remote auditing has become a valuable addition to the auditor’s toolbox and is now recognised within ISO 19011 as a legitimate auditing approach. However, its success depends on thoughtful planning and the application of risk-based thinking.

For internal auditors managing multiple sites, the most effective solution will often be a hybrid audit, combining desktop reviews of documented information with targeted on-site verification of higher-risk and more complex operational processes.


Rather than asking, “Can this audit be conducted remotely?”, a better question is:


“What audit method will provide sufficient, reliable, and appropriate objective evidence to determine whether the management system is both conforming and effective?”



That question lies at the heart of every successful audit.

 
 
 

Comments


bottom of page