Remote audits under IAF MD 4: how to plan ICT audits
How to plan an IAF MD 4 remote audit under the 2025 issue: risk review, client agreement, ICT tests, virtual sites, audit time and scheme limits.
IAF MD 4:2025 sets the rules for using information and communication technology (ICT) in conformity assessment, applicable from 30 January 2026. ICT is optional, but when used the body must assess the risks, agree its use and security measures with the client, confirm everyone has the infrastructure, state in the plan how ICT will be used, use competent people and report how effective it was.
Key takeaways
- IAF MD 4:2025 (Issue 3) applies from 30 January 2026 and covers management systems, validation and verification, persons and product certification.
- Remote auditing needs a documented risk review, mutual agreement with the client and a check of infrastructure before it goes in the plan.
- A virtual site cannot be used where processes happen in a physical environment such as manufacturing or warehousing.
- Scheme rules can be stricter: IFS Food audits are always on-site, and FSSC 22000 limits full remote audits to serious events.
What is an IAF MD 4 remote audit?
An IAF MD 4 remote audit is any audit, or part of one, where the team uses ICT, such as video calls, screen sharing, shared document platforms or drones, in line with IAF MD 4. The current document is IAF MD 4:2025, Issue 3, issued on 30 January 2025 and applicable from 30 January 2026. It replaced the 2023 issue.
The document is short and principle-based. Using ICT is never mandatory, but once you use it as part of your conformity assessment method, compliance with MD 4 becomes mandatory. It covers management system certification, validation and verification, certification of persons and product certification.
IAF MD 4 does not define 'remote audit' as a term. It defines only the virtual site, which matters for scope and audit time.
What does IAF MD 4 require before a remote audit?
- Agreement (4.1.2): ICT use must be mutually agreed between the client and the body, including the information security and data protection measures.
- Fallback (4.1.3): if those measures cannot be met or agreement is not reached, other methods must be used.
- Risks and opportunities (4.2.1): identify and document what could affect the effectiveness of the assessment.
- Feasibility (4.2.2): the application review checks that all parties have the infrastructure for the ICT proposed.
- Plan (4.2.3): the plan identifies how ICT will be used and to what extent.
- Competence (4.2.4): team members can use the technologies and understand their risks and opportunities.
- Report (4.2.6 and 4.2.7): the report states the extent and effectiveness of ICT use and identifies activities at any virtual site.
Clause numbers refer to IAF MD 4:2025. Check iaf.nu for later issues.
How should planners sequence an ICT audit?
Most of MD 4's requirements land before the audit date, which means they land on the planning team.
- 1ReviewDecide which activities suit ICT
- 2Assess riskDocument risks and opportunities
- 3AgreeClient agrees ICT and security measures
- 4TestConfirm connection, tools, access
- 5PlanState ICT use in the audit plan
Book the connection test as a task with a date, not a hope. A failed link on the audit day means the activity has to be covered by another method, which can cost a second visit.
When is a remote audit not an option?
MD 4 says a virtual site cannot be considered where processes must be executed in a physical environment, for example warehousing, manufacturing, physical testing laboratories, installation or repairs to physical products. Scheme owners can go further, and several do.
| On-site | ICT (remote) | |
|---|---|---|
| Observing production, storage or installation | ✓ | ✕ |
| Document and record review | ✓ | ✓ |
| Interviews with staff working online | ✓ | ✓ |
| Auditing a virtual site | ✕ | ✓ |
| IFS Food audit (Version 8) | ✓ | ✕ |
| FSSC 22000 regular audit (Version 6) | ✓ | ICT as a tool; full remote only for serious events |
IFS Food Version 8 states that an IFS Food audit is always performed on-site. FSSC 22000 Version 6 allows ICT as a remote auditing tool during regular audits, with full remote audits limited to serious events under its Full Remote Audit Addendum. Check each scheme before offering remote options; food scheme rules are covered in food safety auditor qualification.
Does an IAF MD 4 remote audit change audit time?
Not automatically downwards. MD 4 says ICT contributes to the total conformity assessment time, as additional planning may be necessary, and that its impact on duration is not limited by the document. A virtual site counts as a single site when calculating conformity assessment time.
So start from the duration your rules produce, such as IAF MD 5 audit time or IAF MD 1 sampling for multi-site clients, then add time for setup and testing where needed. Record your reasoning.
Watch the audit window too. Splitting an audit into a remote part and an on-site part creates two dates, and both must fall inside the window for a surveillance or recertification audit.
Worked example: a hybrid ISO 9001 surveillance
The client
A manufacturer with one factory and a design team that works fully online from home offices. The surveillance is 2 auditor-days.
The plan
Half a day remote for the design team, treated as a virtual site: interviews by video, design records via a shared platform. One and a half days on-site for production, purchasing and the warehouse, because those processes are physical.
The planner records the client's agreement to the video platform and the data handling rules, books a 30-minute connection test a week before, and names the ICT activities in the audit plan.
The scheduling benefit
The remote half-day can sit on a different date from the site visit, for example on an auditor's office day, which frees a travel day elsewhere. See ways to reduce auditor travel time.
Remote audit planning checklist
- ✓Scheme rules allow ICT for this audit type
- ✓Risks and opportunities documented
- ✓Client agreement recorded, including security and data protection
- ✓Infrastructure checked for every participant
- ✓Audit plan states how and how far ICT is used
- ✓Auditors competent in the tools being used
- ✓Virtual sites identified in scope and plan
- ✓Fallback method agreed if ICT fails
ScheduleAI records ICT suitability per client and activity, so remote parts can be scheduled separately from site days while competence, audit windows and travel rules still apply.
ScheduleAI is the audit scheduling software certification bodies use to plan ISO programmes from stage 1 to recertification.
ScheduleAI lets planners schedule remote and on-site parts of an audit as separate activities, each checked for competence, audit window and travel, with ICT agreement tracked on the client record.
Book a demo Estimate your savingsQuestions
What is IAF MD 4?
The IAF mandatory document for the use of ICT for conformity assessment purposes. The current issue is IAF MD 4:2025, applicable from 30 January 2026.
Is remote auditing mandatory under IAF MD 4?
No. ICT use is optional, but when it is used as part of the assessment method, MD 4 must be followed.
Can a whole audit be done remotely?
MD 4 sets no percentage, but a virtual site cannot cover physical processes such as manufacturing or warehousing, and schemes can restrict remote auditing further.
Does remote auditing reduce audit time?
No automatic reduction. MD 4 says ICT contributes to the total time and may need extra planning.
What is a virtual site?
A virtual location where a client performs work or provides a service using an online environment. It counts as a single site when calculating audit time.
Do accreditation bodies accept remote audits?
Yes, where IAF MD 4 and any scheme rules are followed. Your accreditation body may add its own guidance, so check it before offering remote options widely.
What if the video link fails during the audit?
MD 4 does not prescribe a procedure for this, so agree a fallback method in advance and record how the activity was covered. See handling last-minute changes.