IAF MD 4 – Use of information and communication technology (ICT) in audits
Audits (initial certifications, recertifications and surveillance audits) have been and continue to be characterised by a correspondingly high proportion of on-site work. The most important aspect, whether on site or remote, is that the effectiveness and efficiency of an audit process is ensured and that its integrity is guaranteed and can be maintained.
Information and communication technology (ICT) can be one option used in the course of an audit. However, this is not possible in all cases. Based on the IAF and the ISO/IEC standards to which a certification body is subject, there are requirements that must be taken into account when deciding "ICT: yes/no" or "remote audit: yes/no".
For the use of ICT, in 2023 the IAF published an updated mandatory document governing the use of ICT for audit purposes – IAF MD 4:2023.
Definition – delimiting the term "site"
IAF MD 1:2023 (Auditing and certification of management systems in organisations with multiple sites) already distinguishes between permanent, temporary and virtual sites, among others. IAF MD 4:2023 also defines the virtual site, with both definitions being very similar. The definition from IAF MD 4:2023 is as follows:
"Virtual location where a client organisation performs work or provides services in an online environment that allows individuals to carry out processes irrespective of physical locations."
This means that ICT cannot be used across the board for all organisations and industries. Where processes require a physical environment – for example in medical device manufacturing, warehousing, physical testing laboratories or the installation of physical products – ICT cannot be used in full.
One example of a virtual site is a design and development organisation in which all employees perform their work remotely and operate in a cloud environment. However, a virtual site can also be an organisation's intranet or SharePoint, for example.
What does this mean for organisations seeking certification?
The assessment of whether an audit at an organisation can be carried out using ICT is performed by the certification body. The following aspects are taken into account:
- Security and confidentiality: It must be examined how security and confidentiality can be maintained when using ICT. It must also be established whether the use of ICT can take place in accordance with security information, data backup measures and regulations. In addition, it must be ensured that ICT is used by mutual agreement.
- Procedural requirements: Risks and opportunities that may affect the effectiveness of audits for each use of ICT under the same conditions must be considered, including the selection of technologies and how they are managed. This must be documented accordingly, including a description of how ICT is used to optimise the effectiveness and efficiency of the audit while maintaining the integrity of the audit process. When ICT is used for audit purposes, this influences the total audit time, as additional planning may be necessary, which can affect the audit duration.
This entry does not claim to cover all individual requirements of IAF MD 4:2023 in full. Rather, it is intended as a summary of the key requirements – particularly from a customer perspective.