Remote Audits – Is Your Certification Body Following the Intent?

Table of Contents

Remote certification audits: what to expect from your certification body

Remote Audits: Is Your Certification Audit Delivering What It Should?

Remote audits became the norm in 2020, and they’re still here for good reason. Done well, a remote audit saves travel, reaches people across sites and can be every bit as rigorous as an on-site audit.

I use remote methods myself. I hold many of my audit interviews over Teams, and they work because I plan and schedule them, then follow up in writing.

But in certification audits I’ve supported for clients, I’ve seen some certification bodies (CBs) settle into habits that sit a long way from what the guidance intended. The audit becomes document-first: upload everything, answer the emails, and let the auditor decide conformity from the paperwork. And the same habits turn up when the auditor is sitting in your office.

So this article looks at the ISO 9001 Auditing Practices Group (APG) paper on remote audits [1], where practice has drifted, the commercial pressure behind some of it, and how to hold your CB to account.

To be clear, this isn’t an argument against remote audits, and not every CB or auditor works this way. Many don’t. Instead, it’s an argument for remote audits done properly.

What is the APG Remote Audits paper for?

The ISO 9001 Auditing Practices Group is an informal group of experts from ISO/TC 176 and the International Accreditation Forum (IAF). The group wrote its paper Guidance on: Remote Audits (Edition 1, 16 April 2020) [1] early in the COVID era.

It treats remote auditing as one method among several, valuable for its flexibility provided everyone understands the risks and limits. Paraphrasing:

  • Check feasibility and risk-assess each audit, with the auditee. Can auditors and auditees use the technology? Proceed remotely, combine with on-site, or accept the objectives can’t be met remotely.
  • Plan more, not less. A detailed agenda saying what, when and how, with interviewees scheduled and technology tested.
  • Interviews remain part of the method, with what people say verified against other evidence.
  • Pre-supplied documents help with preparation, but carry risks: no chance to clarify, possible manipulation, and the auditee losing sight of what’s sampled.
  • Be honest about time and results. ICT downtime isn’t audit time, and the report should say how far the audit used ICT, how well it worked, and what the team should have audited on site.

The paper’s limits, and what’s changed since 2020

Two caveats. By the APG’s own description, the paper isn’t definitive, isn’t audit criteria, and hasn’t been endorsed by ISO, ISO/TC 176 or IAF. And the APG wrote it for ISO 9001:2015 [11], which remains in force during the transition to ISO 9001:2026 [8], and it says nothing specific about OH&S.

Its reference documents have also moved on. For example, ISO 19011:2026 [6] replaced the 2018 edition on 27 May 2026. IAF MD 4 [2] is now Issue 3 (2025), applicable from 30 January 2026. And since 1 January 2026, IAF and ILAC have become Global ACI [9], with specified IAF documents remaining valid until Global ACI adopts equivalents.

Guidance vs requirement

Requirement: For accredited certification, IAF MD 4:2025 [2] requires ICT use to be agreed in advance, ICT risks to be documented, the plan to show how ICT will be used, and reports to record its extent and effectiveness (4.1.2, 4.2.1, 4.2.3, 4.2.6). IAF MD 5 [3] governs audit time; IAF MD 22 [4] adds OH&S requirements. ISO/IEC 17021-1:2015 [5] covers audit time, planning, appeals and complaints.

Guidance: The APG paper and ISO 19011:2026. Useful, but not audit criteria.

Our view: The mandatory documents are brief, but clearer than many people realise on planning, audit time and OH&S. The APG paper is a fair yardstick for a conversation with your CB.

Where certification audit practice has drifted

Here are five habits to watch for. In my experience they’re not universal: I’ve also seen remote Stage 1 audits planned, communicated well ahead and run to schedule with proper opening and closing meetings. But where these habits take hold, they hollow out the audit.

1. Not recognising the limits of remote methods

Some things you can’t see down a camera, or only if the auditee chooses to show them. In audits I’ve supported, I’ve seen requests for photos of site work used instead of observation or a simple conversation. A photo the auditee chose to take isn’t the auditor seeing the work, which is the “partial view” risk the paper describes [1]. If the method can’t meet the objective, then the plan should change, not the standard of evidence.

2. Not being clear about how the audit will be delivered

Is the audit remote, on site or hybrid, and on which days? That should be in writing well ahead. Otherwise you end up pulling people off the tools for an auditor who’s dialling in, or process owners are unavailable because nobody told them when the auditor would need them.

I’ve had to ask a CB directly whether an upcoming audit would be remote, only to hear that remote was the default that year. A default isn’t a risk assessment. MD 4 requires the plan to identify how and to what extent ICT will be used (4.2.3) [2]. So ask for it.

3. Document-first auditing

This is the habit I see most, and it does the most damage. The audit becomes a stream of clause-labelled email requests, or a portal checklist: upload everything first and the auditor will determine conformity from what’s there. Sometimes the requests are for records the standard doesn’t require, as I’ve noted about management review documented information.

A document review has its place, as I explained in It’s More Than Just an Audit Checklist. But it’s preparation for the audit, not the audit itself. The APG paper says the auditor should verify material gathered this way with other evidence during the audit [1]. When it isn’t, the audit becomes a paperwork exercise: your team does the heavy lifting, and the conclusion rests on what you chose to upload. That isn’t what the guidance intended.

However, it’s not purely a remote problem. For example, I’ve had a client describe an on-site audit where the auditor sat in their office and sent email requests all day.

4. Not interviewing auditee representatives

ISO/IEC 17021-1 treats interviews, alongside observation and document review, as ways of obtaining and verifying audit information (9.4.4) [5]. Yet I’ve seen audits where the auditor spoke to almost nobody beyond the management system representative or the consultant. I’ve had an auditor acknowledge that earlier remote audits only involved the system representative, and that it would be better to speak with top management.

Records tell you something was written down. People tell you whether the system works.

5. Using remote methods where they don’t suit, particularly OH&S

The APG paper doesn’t address OH&S, so the IAF documents matter more here. Remote OH&S audits aren’t off limits: auditors can still review documents and run interviews remotely. But in its section on initial certification audits, IAF MD 5 states plainly that, for OH&S, process control and OH&S risk control can’t be audited using remote techniques (4.5) [3].

IAF MD 22 [4] requires OH&S audit teams to interview specified people, including management legally responsible for OH&S, employee OH&S representatives, and managers and permanent and temporary employees (G 9.4.4.2). It also expects audit teams to sample temporary sites, such as construction sites. And in its appendix on legal compliance, MD 22 itself notes that too much audit time spent on office-based review is a problem that occurs with some frequency.

Despite this, in audits I’ve supported, I’ve seen OH&S elements audited largely through emailed records and photos, including worker consultation (ISO 45001 [7], Clause 5.4) assessed mainly by requesting minutes and toolbox records. If you’ve read my post on worker participation in health and safety, you’ll know why I think a conversation with workers tells you far more.

The commercial pressure behind the drift

Why do these habits stick? I think part of the answer is commercial.

CBs are businesses. Every audit day costs them an auditor’s time, and in my experience many rely on contract auditors. Travel, preparation and report writing all add cost. As a result, there’s an obvious incentive to reduce auditor utilisation costs: minimise preparation, keep audit time tight, and fit the audit into as few days as possible.

Remote and document-first formats suit that incentive: no travel, no site walk, and evidence-gathering shifts from the auditor to the auditee.

In my experience, the risk shows up as a lack of audit preparation:

  • The auditor hasn’t reviewed the organisation’s context, risks, documents or previous audit reports before the audit starts.
  • The audit plan is generic, not tailored to the organisation’s processes, sites or risks.
  • Document requests arrive mid-audit, without context, sometimes for material already supplied.
  • Audit days are compressed: late starts, long evenings and requests arriving after hours.
  • Reports carry over generic or out-of-date content that doesn’t reflect your organisation.

An auditor has told me that whether they look at documents before the audit day depends on their workload. That’s honest, but it’s the problem in a sentence.

I can’t see inside any CB’s costing, and I’m not suggesting any CB sets out to short-change clients. But it’s a real risk, and the standards are clear that audit time includes preparation.

What the standards say about audit time and planning

  • Audit time is set per client. ISO/IEC 17021-1 requires the CB to determine the time needed to plan and accomplish a complete and effective audit, considering factors including complexity, risks and prior audit results, and to record its justification (9.1.4) [5].
  • Planning is required. An audit plan suited to the audit’s objectives and scope is established before each audit, including any remote activities (9.2.3) [5].
  • Preparation counts. IAF MD 5 says audit time includes off-site planning and document review, and the time from opening to closing meeting, physical or virtual, should typically be at least 80% of the calculated audit time (2.1) [3].
  • No compressing. Audit days can’t be reduced at the planning stage by scheduling longer hours (2.2.2) [3]. For OH&S, MD 22 applies MD 5 (G 9.1.4) [4].
  • Remote isn’t a discount. MD 4 says ICT use contributes to total audit time because it may need extra planning (4.2.5) [2]. The APG paper adds that time lost to ICT problems shouldn’t count as audit time [1].

In short, preparation is part of the audit. If it’s been squeezed out, so has part of what you’re paying for.

Why this matters to certified organisations

You’re paying for audit days, and clients rely on your certificate in tenders and prequalification. When the method drifts, you wear the cost.

HabitWhat it costs you
Unclear delivery methodWasted time, people unavailable, rescheduling.
Document-first auditingAdmin burden, duplicate uploads, requests for records you don’t need.
Few or no interviewsWeak assurance; your people never see the audit.
Squeezed preparationGeneric plans, late requests, findings that miss your real risks.
Remote where unsuitable (OH&S)Site risks missed; a certificate that says less than people assume.

We’ve successfully challenged findings where an auditor expected documents the standard doesn’t require. But nobody should have to spend that time.

Guidance for organisations: be informed and prepared

Before the audit: ask your CB, in writing

  • The audit plan: Whether each day is remote, on site or hybrid, and why.
  • The risk assessment: How the CB assessed remote suitability.
  • Audit time: The days in your agreement versus the plan. For initial certification, MD 5 requires the CB to give you its audit time determination and justification as part of the contract (4.4) [3].
  • Preparation: Whether the auditor will review your previous report, context and documents beforehand.
  • Interviews: Who, and when. For ISO 45001, how the auditor will cover the MD 22 interviewees.
  • ICT arrangements: The platform, a test, a backup, and how the CB will handle screenshots and shared documents.
  • OH&S sampling: Which sites, including temporary sites, and which work the auditor will see in person.

During the audit

  • Insist on interviews, and offer the people who do the work.
  • Log requests, meetings, start and finish times, and time lost to ICT problems.
  • Ask for the requirement behind any request you’re unsure about.
  • Raise disagreements before the closing meeting and ask the auditor to record them.

After the audit

  • Check each finding states the requirement, evidence and gap.
  • Check the report is accurate: audit type, attendees, deviations from the plan, and the extent of ICT use.
  • Finally, compare time on audit against your agreement.

How to hold your certification body accountable

In my experience, most CBs will accept a well-evidenced challenge. If not, there’s still a path.

StepWhat to do
1. Check what was agreedYour certification agreement, the audit plan and any written confirmations.
2. Give written feedbackTo the lead auditor and the CB, with facts, dates and the requirement involved.
3. Appeal or complainISO/IEC 17021-1 requires CBs to have documented appeals and complaints processes, handled independently (9.7 and 9.8) [5]. Use them.
4. Escalate to the accreditation bodyIn Australia and New Zealand, usually JASANZ.

JASANZ (Joint Accreditation System of Australia and New Zealand) [10] investigates complaints about the conduct or performance of the bodies it accredits. It won’t resolve commercial disputes, and expects facts, evidence and the steps you’ve already taken, so go to the CB first. Before you escalate, check your certificate to confirm who accredits your CB.

If you want support, look for the qualities I described in choosing your management system consultant.

Final Thoughts

The APG paper describes remote auditing as a planned, agreed and risk-assessed method that still depends on people and live evidence. The IAF documents are clearer still.

Where practice has drifted, in my experience it’s mostly into document-first auditing, often with too little preparation behind it, whether the auditor is remote or in the room. That isn’t what the guidance intended, and you don’t have to accept it.

After all, your certificate is only as meaningful as the audit behind it. So, are you getting the audit you pay for?

Speak with Us about your Audit Needs

DBell Consulting helps WA organisations prepare for certification and surveillance audits, review audit plans and reports, and respond to findings. Speak with us to discuss your audit needs, or please visit our Contact Us page.

References and further reading

  1. Guidance on: Remote Audits. ISO 9001 Auditing Practices Group (ISO/TC 176 and IAF). Edition 1, 16 April 2020. committee.iso.org (PDF). Other APG papers: ISO 9001 Auditing Practices Group.
  2. IAF MD 4:2025 – IAF Mandatory Document for the Use of Information and Communication Technology (ICT) for Conformity Assessment Purposes. International Accreditation Forum. Issue 3, issued 30 January 2025, application date 30 January 2026. iaf.nu (PDF).
  3. IAF MD 5:2023 – Determination of Audit Time of Quality, Environmental, and Occupational Health & Safety Management Systems. International Accreditation Forum. Issue 4, Version 3, issued 14 June 2023 (application date 7 May 2020). iaf.nu (PDF).
  4. IAF MD 22:2023 – Application of ISO/IEC 17021-1 for the Certification of Occupational Health and Safety Management Systems (OH&SMS). International Accreditation Forum. Issue 2, Version 2, issued 14 June 2023 (application date 7 May 2020). iaf.nu (PDF).
  5. ISO/IEC 17021-1:2015 – Conformity assessment – Requirements for bodies providing audit and certification of management systems – Part 1: Requirements. ISO/CASCO. Edition 1, June 2015 (last confirmed 2020). iso.org.
  6. ISO 19011:2026 – Guidelines for auditing management systems. ISO. Edition 4, published 27 May 2026. iso.org.
  7. ISO 45001:2018 – Occupational health and safety management systems – Requirements with guidance for use. ISO/TC 283. Edition 1, March 2018 (amended 2024; revision under way). iso.org.
  8. ISO 9001:2026 – Quality management systems – Requirements. ISO/TC 176/SC 2. Edition 6, published 16 September 2026. iso.org.
  9. Global ACI Documents, including the IAF/ILAC Documents Cross-Reference Table (last updated 14 September 2026). Global Accreditation Cooperation Incorporated. global-aci.org. Current IAF documents are also listed on the IAF documents page.
  10. Complaints. JASANZ (Joint Accreditation System of Australia and New Zealand). Page accessed 11 October 2026. jasanz.org.
  11. ISO 9001:2015 – Quality management systems – Requirements. ISO/TC 176/SC 2. Edition 5, 2015; remains in force during the transition to ISO 9001:2026. iso.org.

How this article uses its sources

Source and status note: This article discusses the ISO 9001 Auditing Practices Group (APG) paper “Guidance on: Remote Audits” (Edition 1, 2020) [1]. We’ve paraphrased it and the other documents cited, not reproduced them.

In this article, ISO requirements are the “shall” statements in published standards; for certification bodies these sit in ISO/IEC 17021-1:2015 [5].

Mandatory documents include IAF MD 4:2025 (ICT use) [2], IAF MD 5:2023 (audit time) [3] and IAF MD 22:2023 (OH&S certification) [4], which remain valid under Global ACI until equivalent Global ACI documents are adopted [9]; check with your CB which version it applies.

APG guidance is non-definitive auditing guidance: by the APG’s own description it isn’t intended as requirements, mandatory audit criteria or an industry benchmark, and it hasn’t been endorsed by ISO, ISO/TC 176 or IAF.

The APG paper addresses ISO 9001 only (it was written for ISO 9001:2015, which remains in force during the transition to ISO 9001:2026) and predates ISO 9001:2026, ISO 19011:2026 and IAF MD 4 Issue 3. ISO 19011:2026 is guidance.

DBC commentary, including our views on commercial pressure, is our professional opinion based on our experience. It isn’t a formal interpretation of any standard or a statement about any particular certification body. Refer to the current published documents and your certification body’s requirements for your own situation.

Accessing Official copies of ISO Standards

ISO management system standards are protected by copyright, with reproduction subject to certain restrictions. This includes the standards being subject to licensed purchasing via the ISO website and approved distributors. If you require a copy of these standards, visit the ISO website, or follow the below links for specific standards:

Share the Post:
Related Posts