For internal auditors, ISO 9001:2026 changes specific parts of the audit workflow — planning now requires a documented objective, conducting means checking a few genuinely new checkpoints, and management review verification includes one new required input. The core methodology — evidence gathering, the process approach, root cause discipline — stays the same.
An internal audit that doesn't account for these specific requirement changes still functions, but it won't fully verify conformance to the standard the organization is actually certifying against. This guide follows the audit workflow itself — planning, conducting, and management review verification — and explains exactly what an auditor needs to do differently at each stage under ISO 9001:2026 — written by Maria Falbo, a Lead Auditor with decades of ISO 9001 experience.
The fundamentals of conducting an ISO 9001 internal audit are unchanged under 2026 — the same evidence-gathering methods, the same emphasis on following the process approach rather than a rigid checklist, the same root cause discipline for corrective action. For the full methodology, see our ISO 9001 Internal Audit: The Complete Guide and our how to conduct guide.
What changes is narrower and more specific: a handful of points across the audit workflow where the standard now expects something it didn't explicitly require before. For the full technical detail behind each one, see our ISO 9001 Requirements Explained guide.
When building an audit plan, you now need a documented reason the audit is happening — something beyond "it was next on the schedule." Build this in as its own field alongside scope and criteria if your template doesn't already have one.
You'll also want to confirm, before the audit, whether the organization has restructured its risk and opportunity documentation to reflect the split into separate subclauses. If it hasn't yet transitioned that content, your planning should account for auditing against whichever structure the organization is currently actually using — the old combined approach or the new split one.
Our ISO 9001 consulting services can help your audit team prepare for the transition.
A few specific checkpoints are worth adding to your usual evidence-gathering. When reviewing risk and opportunity documentation, check that the register genuinely distinguishes threats from opportunities, rather than listing both under one heading and calling it done. When reviewing interested party documentation, confirm that a decision was made about which of those expectations the system is meant to cover — a plain list of names and wants isn't enough on its own.
When interviewing staff for awareness, pay attention to whether someone can explain why a control matters, not just recite the steps — that's a stronger signal of the quality culture than any rehearsed answer about policy. And where the organization references external providers, confirm the terminology and scope match the broader "externally provided processes, products, or services" language rather than the narrower "outsourced" framing.
The checkpoint I'd flag as easiest to miss in the moment is the interested party filtering decision. It's tempting to see a well-populated stakeholder list and move on, satisfied the requirement is met. The actual point worth verifying is one level deeper — whether someone made, and captured, a decision about which of those expectations the QMS is actually built around. A long list of stakeholders with no filtering decision behind it is a finding, even if it looks thorough at a glance.
Findings and reporting formats are not changing. What's worth adding to your management review verification specifically is confirming it showed up as something the group actually addressed.
This is the item that could be missed most often in the first year or two after transition, simply because it's easy to assume a general strategy discussion covers it. Ask directly: when were interested party expectations last raised as its own point at management review, and who can point to that specific discussion?
None of these changes require a fundamentally new skill set, but auditors do need a specific understanding of what's different before their next audit — not just a general sense that "the standard was updated." A brief, targeted refresher covering these specific workflow points is usually sufficient; a full retraining isn't necessary for auditors already competent under the 2015 edition. For the organization's broader transition sequence, including where auditor training fits, see our how to transition to ISO 9001:2026 guide. For a full breakdown of every change behind these workflow points, see our ISO 9001:2026 Key Changes guide.
No — there's no formal retraining requirement for individual auditors. A targeted refresher on the specific workflow changes is generally sufficient for auditors already competent under the current edition.
No — auditors benefit from understanding these changes ahead of the organization's own transition, since they'll likely be the ones verifying whether the transition work is complete.
No — the classification approach itself is unchanged. These changes affect what gets checked, not how findings are subsequently categorized once identified.

Maria Falbo has over 25 years of experience working as a Lead Auditor for certification bodies worldwide. She founded Logix ISO with the mission of making expert-level ISO training accessible to organizations of all sizes. Her work spans Quality, Environmental, Occupational Health and Safety, Food Safety, Automotive, and Energy management systems.
Learn more about Maria →Auditor readiness support and transition planning