Remote ISO internal audits by video conference
Internal Audits
April 24, 202611 Min Read
Back To Blog

Remote ISO Internal Audits: A Practical Guide for Audit Teams

Remote auditing is no longer something organisations do because they have to. It has become a practical option for internal audit teams managing ISO 9001, ISO 14001, ISO 45001 and ISO 27001 programmes, especially when sites are spread across different locations or countries.

But running remote ISO internal audits well is not as simple as moving from a meeting room to a video call. It takes proper planning, clear communication and the right approach to evidence. This guide looks at what works, what does not, and how to build remote audits into your programme without losing the rigour your management system needs.

What Are Remote ISO Internal Audits?

Audit team running a remote ISO internal audit by video call

In simple terms, remote ISO internal audits are audits conducted without the auditor being physically present at the location being audited. Instead of walking the site, the auditor works through video calls, screen sharing, document reviews and live walkthroughs using a camera or mobile device.

ISO 19011:2018 recognises remote auditing as a valid technique. It is not a shortcut or a lesser version of auditing. When planned properly, it can be just as effective as being on site, particularly for document heavy processes and interviews.

The key difference from remote external audits is that these are your own internal audits. You have more control over how they are run, which gives you flexibility to adapt the approach to what suits your organisation.

When Remote ISO Internal Audits Make Sense

Audit team collaborating remotely across locations

Remote audits are not second class audits. They are the same work, just using different ways to see and verify what is going on.

Where Remote Audits Work Well

Remote ISO internal audits tend to work best where:

The process already lives in systems and documents

If most of the work happens in software, forms or workflows, a screen share will usually show you what you need. Reviewing policies, procedures and documented information is often more efficient remotely, because everyone can see the same version on screen and navigate quickly.

You are checking how electronic systems are used

For example, how nonconformities are logged, how records are approved, how access rights are managed. A user walking you through the system in real time is often clearer than standing behind them on site.

You are verifying training and competence records

Training matrices, certificates, role profiles and HR records can be reviewed just as well through a shared screen as in a meeting room. The important part is the content and the logic, not where you sit.

You are following information security processes, especially for ISO 27001

Access control, backups, incident logs, change management systems and monitoring tools are all naturally suited to remote ISO internal audits, because they are digital by design.

You need to speak to people who are not all in one place

For roles that are office based, hybrid or spread across locations, a remote session may actually give you better access to the right people in one go.

Where Remote Methods Are Weaker

Shopfloor activity that is harder to judge through a remote audit

Remote methods become weaker when your judgement depends heavily on what you see, hear and feel in the physical environment, for example:

Housekeeping, layout and safety culture on a busy shopfloor or site

A short video clip rarely gives you the same depth as walking the area, noticing what people do when they are not “on show”, or spotting small signs of a strong or weak culture.

Use of tools and equipment in high risk environments

For tasks with serious safety implications, you may need to see how people work, how supervision is done and how controls are applied in real time, not just how they are described.

Storage and labelling of materials and waste

Details around segregation, labelling, condition, access routes and signage are far easier to judge in person than through a handheld camera.

In practice, many organisations are moving towards a hybrid model. Office based parts of the audit are done remotely, high risk physical activities are checked in person, and some processes alternate between remote and on site from one cycle to the next. The key is to decide this consciously, not at the last minute.

Planning Remote ISO Internal Audits in a Risk Based Way

Planning a risk based remote ISO internal audit programme

The planning step makes or breaks remote work.

Start with the basics from ISO 19011:

  • Define the objectives. Why are you auditing this process now?
  • Set the scope and criteria. Which locations, activities and requirements are in scope?
  • Consider risks. What could go wrong if you tried to audit this process remotely?

Then think through:

  • Which parts of the process you can see effectively through documents, screens and conversations
  • Which parts really need eyes on the ground
  • Whether the people you need are comfortable and equipped to join remote sessions
  • How you will manage time zones if you are covering different regions

Remote ISO internal audits should be a planned part of your audit programme, not an emergency choice when nobody is available to travel. A simple rule of thumb is to make the remote or on site decision at the planning stage, record your reasoning, and be ready to explain it to external auditors if asked.

Tools and Evidence for Remote ISO Internal Audits

Screen sharing and video tools used in a remote ISO audit

You do not need an exotic tech stack to run good remote ISO internal audits, but you do need to be deliberate.

Typical tools include:

  • Video conferencing for interviews and virtual tours
  • Screen sharing to see systems in real time
  • Secure file sharing for records and screenshots
  • A central audit system to capture notes, evidence and findings

The bigger issue is the quality of evidence, not the platform. During remote audits, you should still look for:

  • Demonstrations of how a process actually runs, not just written procedures
  • Records with clear dates, identifiers and links to real work
  • Visual confirmation where appropriate, for example via a live video walkaround

You also need to think about confidentiality and data protection. Avoid sensitive evidence being shared over personal email or chat apps. Set simple rules up front about how information will be exchanged and where it will be stored.

Challenges Auditors Face During Remote ISO Audits

Audit team managing technology challenges during a remote session

Remote ISO internal audits are not without their problems. Common issues include:

  • Technology failures. Poor internet, dropped calls and frozen screens can waste time. Have a simple backup plan, such as switching to audio only and sharing documents afterwards.
  • Harder to read the room. On site, you pick up signals from body language and the feel of a workplace. That is much harder through a screen.
  • Selective evidence. There is a risk that auditees only share what they want you to see. Without being physically present, it takes more skill to probe deeper.
  • Video fatigue. Long remote sessions are exhausting for everyone. Shorter blocks with breaks work much better.

None of these are reasons to avoid remote ISO internal audits. They are reasons to plan them properly, be honest about their limits and balance them with on site work where it matters.

Collecting Evidence During Remote Audits

Reviewing audit records and evidence during a remote session

Evidence is what separates an audit from a conversation. During remote ISO internal audits, you need to be more deliberate about how you collect and verify it.

Practical approaches include:

  • Screen sharing for reviewing documents, records and system data in real time
  • Live video walkthroughs where the auditee walks through a site or workspace with a camera
  • Photographs and videos submitted by auditees, ideally with timestamps and context
  • Secure file sharing for uploading records, certificates, inspection reports and other evidence

The most important point is to verify what you are seeing. Ask follow up questions. Request additional records. Cross check what you are told with what the documents show. The same principles apply as on site, you just need to be more intentional about it.

Using PDCA for Remote Audit Programmes

Reviewing a remote audit programme using the PDCA cycle

The PDCA cycle applies to remote audits just as it does to any other part of your management system.

Plan

Decide which audits will be remote, which will be on site and which will be a mix. Base this on risk, process type and practical factors.

Do

Conduct the audits using the agreed approach, technology and methods.

Check

After each cycle, review how the remote ISO internal audits went. Were findings meaningful? Was evidence adequate? Did the technology work?

Act

Adjust your programme based on what you learned. Move certain processes back to on site if remote did not work. Expand remote coverage where it did.

Over time, this gives you a programme that is practical, balanced and based on evidence rather than habit.

Making Remote Audits Easier with the Right Tools

Managing remote ISO internal audits across multiple sites using emails, spreadsheets and shared folders gets messy fast. Findings end up in different documents. Evidence sits on someone's laptop. Actions get lost.

That is one of the reasons we built iAudit Global. It is ISO audit management software designed around the PDCA cycle, where your checklists, findings, evidence and actions all sit in one place, whether the audit is remote or on site.

Your audit data stays with your organisation. We have no access to it.

If you are looking for a simpler way to manage your audit programme, we are running a pilot. You can register your interest here.

Register interest at surveys.iaudit.global

Mathew Chiweda

Author

Conclusion

Remote ISO internal audits are here to stay. They offer real benefits when planned well and used for the right processes, but they are not a replacement for on site audits where physical verification matters.

The key is good planning, clear communication, proper evidence collection and a PDCA approach that helps you refine the programme over time. Get those right and remote audits become a practical, permanent part of how you manage your ISO programme, not a compromise you only use when you have no other choice.

Ready to upgrade?

Ready To Upgrade Your
Audit Process?

Join the global community of auditors who have moved beyond spreadsheets. Create oversight in days, not months.

Just pay what you see
No hidden fees
iAuditGLOBAL
OVERVIEW
Dashboard
MANAGEMENT
Company
Users
Self Assessment
Gap Analysis
Audit Program
Findings

Audit Summary

Overall compliance status

49%
Requires Improvement
Comply
OFI
NC

Clause Breakdown

Compliance by ISO clause

4. Context
11%
5. Leadership
90%
6. Planning
33%
7. Support
0%
8. Operation
50%
9. Performance
50%
10. Improvement
60%
Start free trial