« ISO auditor » is a phrase everyone uses and no standard defines. ISO publishes standards; it certifies no one, keeps no register of individuals and awards no personal titles. What the phrase actually covers is three different jobs, with three levels of requirement, three possible employers and three routes that have almost nothing in common. Confusing them is the leading cause of disappointment: people take a five-day course expecting to become certification auditors, and end up competent to audit their own company, which is already a lot but is not the same thing.
The essentials
- No official title: ISO publishes standards, it certifies neither people nor bodies. There is no « ISO auditor diploma ».
- Three levels: internal audit (first party), supplier audit (second party), certification audit (third party). The conduct reference is the same; the independence requirements are not.
- The conduct reference: ISO 19011:2026, fourth edition, which cancels and replaces ISO 19011:2018.
- It is not a requirements standard: ISO 19011 gives guidelines. You do not get certified to it, you use it.
- The only level that requires outside recognition is third party. For the other two, your own organization decides on your competence.
What the phrase does not mean
The word « auditor » appears in no management system standard as a status to obtain. ISO 9001, ISO 14001 and ISO 45001 require internal audits at planned intervals, and require auditors to be selected so as to ensure the objectivity and impartiality of the process. They do not say how to become an auditor, nor who is entitled to be one. The question is referred to competence, and competence is demonstrated, not purchased.
This is why the same person can be a perfectly legitimate auditor inside their company and have no existence at all for a certification body. The two situations do not contradict each other: they simply describe different jobs.
The three levels, and what really separates them
ISO 19011:2026 distinguishes audits by the party conducting them. The difference is not one of difficulty, it is one of independence: the further you stand from the audited organization, the more formal the required guarantees.
| Level | Who audits whom | What is required of you |
|---|---|---|
| First party internal audit |
Your organization audits itself. | The competence defined by your organization, and impartiality: you do not audit your own work. |
| Second party supplier audit |
You audit an external provider, or a customer audits you. | The same competence, plus command of the contractual reference and of the relationship. No external recognition is required. |
| Third party certification |
A certification body audits an organization in order to issue a certificate. | Being qualified by that body, which itself works under accreditation. This is the only level where your route is checked by someone else. |
Remember the practical consequence: for the first two levels, no outsider will validate your title. Your organization sets the competence criteria, applies them, and keeps the evidence of its evaluation. For the third, you enter a system where your qualification is verified by someone else.
What ISO 19011:2026 asks of an auditor
The fourth edition, published in 2026, cancels and replaces the 2018 edition. It keeps the numbering of clauses 4 to 7, which makes the transition easier, and deals with auditor competence in clause 7. The logic is constant: competence is not a diploma, it is the combination of knowledge, skills and behaviours, evaluated and then maintained.
The seven audit principles, now numbered 4.2 to 4.8, form the foundation found at all three levels: integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach, risk-based approach. These are what an auditor falls back on when no procedure covers the situation, and they are how a trained auditor is told apart from an improvised one.
The most common misconception. You do not get certified « to ISO 19011 ». It is a guidance standard, not a requirements standard: it is not certifiable, neither for an organization nor for a person. A body offering you an « ISO 19011 certification » is selling something other than what its title announces.
Which route, for the level you are aiming at
The three levels do not demand the same investment, which is why « how do I become an ISO auditor » has no single answer.
To audit internally, the entry is the most direct. What you need to master: the target standard, sampling, interview technique and how to word a finding. One point deserves to be said plainly: the difficulty of an internal audit is not technical, it is relational. You are auditing colleagues you will see again on Monday.
To audit suppliers, add contract reading and the ability to hold a position in front of an organization that is not yours and has no reason to make your task easy.
To audit for certification, the route is mapped out and long. This is where recognized lead auditor training and professional registers come in. We have covered it elsewhere rather than summarize it badly here:
- Becoming a CQI and IRCA certified ISO 9001 auditor: the full route, from training to registration.
- CQI and IRCA ISO 9001 auditor training: the programme: what the five days cover, the prerequisites and the assessment.
- Passing the ISO 9001 quality auditor exam: the format of the paper and the writing traps.
Where to start, in practice
Whatever level you are aiming at, the first move is the same: conduct a real audit, on a narrow scope, with a checklist. It is when wording a first finding that you discover the gap between knowing a standard and being able to audit against it.
Our free ISO 9001 audit checklist covers the key requirements of the standard, with the clause next to each question. It is enough for a first internal audit. To go further, the ISO 9001 auditor pack adds the evidence to look for against each requirement, the wording of findings and the audit conduct documents.
This article draws on ISO 19011:2026, fourth edition. It presents audit principles and levels; it does not replace reading the standard, nor the rules specific to each certification body, which sets its own qualification criteria.