Start a free trial
Menu

Internal, external, second-party: the audits that decide compliance - and contracts

The three kinds of compliance audit - internal, certification, and second-party customer audits: what each requires, what auditors look for, and how findings affect contracts and tenders.

"Audit" is one word doing several jobs. When a colleague says an audit is coming, it matters enormously which kind they mean: an internal audit you run on yourself, a certification body's external audit, or a customer arriving to inspect you before they sign. Each has a different purpose, a different auditor, and a different set of stakes - and, for the last two, direct consequences for contracts and tenders. This guide separates them and covers what an auditor actually looks for and how findings ripple outward.

Audits are the mechanism behind both compliance and certification: they are how "we meet the requirements" gets tested rather than asserted. If the distinction between compliant and certified is still fuzzy, this guide sets it up; here we go deep on the audits themselves.

The three parties, and why the label matters

Audits are conventionally grouped by who is auditing whom:

  • First-party (internal) audit - you audit yourself. Your own people (or someone you hire to act on your behalf) assess your management system against the standard and your own procedures.
  • Second-party audit - a party with a direct interest audits you. In practice this is almost always a customer (or a prospective one) auditing a supplier before or during a contract.
  • Third-party audit - an independent body with no stake in the outcome audits you. This is the certification audit; the "third party" is precisely what gives its certificate value.

The labels are not academic: a customer audit and a certification audit can examine the same system and reach the same findings, but the consequences differ completely - one affects a single commercial relationship, the other a certificate every customer relies on.

Internal (first-party) audits: auditing yourself, honestly

An internal audit is your organisation checking its own management system against the standard and its own documented procedures. Under ISO 9001 it is not optional - clause 9.2 requires it - but its real value is not compliance for its own sake: it is a rehearsal and an early-warning system, finding problems before an external auditor or a customer does, while they are still cheap to fix.

It is an improvement tool, not a policing function. Run as a hunt for someone to blame, an internal audit just teaches people to hide problems until the auditor leaves. Run as the cheapest place in the organisation to find a fault - before it reaches a customer or a certificate - it earns the honesty it depends on. The target is the system, never the person.

Running an effective programme. Clause 9.2.2 asks you to plan the programme around the importance of each process, the changes affecting the organisation, and the results of previous audits - a formal way of saying audit what matters, and what has given trouble, more often. Four things separate a programme that finds problems from one that just fills a schedule:

  • Risk-based scheduling. Cover the whole system over a cycle, but not evenly: a stable, low-risk process might be audited once, a safety-critical, recently changed, or trouble-prone one several times a year.
  • Auditor competence and independence. An auditor must know the standard and the process well enough to tell a real gap from harmless variation, and be independent of the area - nobody audits their own work. In a small firm that means cross-auditing, or hiring an external auditor to act on your behalf. ISO 19011 is the international guideline for auditor competence and impartiality.
  • Audit checklists. A checklist turns the standard and your procedures into a concrete list of things to look for and sample, so two auditors cover the same ground and this year's audit is comparable to last year's. It is a floor, not a ceiling - a good auditor follows the evidence past it.
  • The audit lifecycle. Every audit runs the same arc: plan (scope, criteria, schedule), conduct (sample records, interview, observe, gather objective evidence), report (write up and classify findings), and close and verify (agree corrective actions, implement them, confirm they worked). That last step is the one most often skipped - an audit whose findings are never verified closed is only half an audit.

A worked example. A manufacturer's internal auditor reviews document control (clause 7.5) and finds three operators working from a superseded version of a work instruction updated two months ago. That is a finding. Caught internally, it costs an afternoon and a fix to the mechanism that let it happen; caught by a certification auditor, it becomes a nonconformity on your record; caught by a customer, a reason to doubt everything else.

What auditors look for is consistent, internal or external: conformity with the standard and your procedures, evidence you can show rather than assert, effectiveness (is it working, or just paperwork?), and follow-through (were earlier problems fixed at the root, or patched?).

What a good nonconformity looks like

Raised internally or by an external auditor, a nonconformity is only useful if it is written well. A finding that reads "document control needs improvement" is worthless: it cannot be argued, root-caused, or verified closed, because there is nothing specific to re-check. A good one states three things, in order:

  • The requirement. The specific clause of the standard, or your own procedure, that was not met - here, ISO 9001 clause 7.5.3, which requires documented information to be available and suitable for use where and when it is needed.
  • The objective evidence. What was actually observed, specific enough that anyone could re-check it: "at workstations 4, 7 and 9, operators were working to revision B of WI-114, superseded by revision C issued two months earlier." Not an opinion - the fact.
  • The gap. The sentence that joins the two: current versions must be available at the point of use; three point-of-use copies were out of date; therefore the requirement is not met.

Written that way, the finding is closable - you confirm the fix by re-checking those workstations. Vague findings fail because you can never prove they are resolved.

Fixing the mechanism, not the instance. A well-written finding still tells you only what is wrong, not why. Root-cause analysis closes that gap, and the simplest tool is to keep asking "why" until you reach something worth changing. Walk the superseded-instruction case through it:

  • Why were operators using the old revision? The current one never reached their workstations.
  • Why not? The update was issued in the document system, but shop-floor copies are printed and posted at each station, and nobody reprinted them.
  • Why did nobody reprint them? Nothing in the change procedure assigns responsibility for replacing point-of-use copies when a document is revised.
  • Why is that step missing? Document control was written for an office where everyone reads on screen, and never adapted when printed copies went out to the floor.
  • Why was it never adapted? Change control is owned by quality, who don't see how documents reach the floor, and no review caught the gap.

The root cause is not "three careless operators" but a change procedure with no controlled step for withdrawing and replacing point-of-use copies - so any future revision can silently fail to reach the floor. Add that step, verify old copies are removed, and the whole class of problem closes, not just this instance. That is the distinction clause 10.2 draws between correction (reissue the document) and corrective action (fix why it was wrong).

External (third-party / certification) audits: the independent verdict

The certification audit is the third-party assessment covered in how certification works: a Stage 1 readiness review, a Stage 2 assessment of the system in operation, then annual surveillance and a three-year recertification. Here the point to stress is how findings are graded, because that is what determines the stakes:

  • Major nonconformity - a requirement is not met, or a part of the system has broken down. A major must be resolved with evidence before a certificate is issued or maintained; unresolved, it blocks certification or can lead to suspension.
  • Minor nonconformity - an isolated lapse against a requirement. Usually handled with a corrective-action plan verified at the next visit.
  • Opportunity for improvement - not a failure and not required, but a suggestion worth considering.

How the line is drawn. Major versus minor is a judgement of scope and impact, not a fixed tariff. A finding is major when a requirement is unaddressed, a process has broken down rather than slipped, or the lapse threatens conforming product or the system's integrity; minor when the system is otherwise working and the slip is isolated. One stale document is a minor; the same finding across several unrelated processes is a broken document-control process, raised as a single major - the pattern, not the instance, is the failure.

What an opportunity for improvement means in practice. An OFI is not a nonconformity: no requirement is breached and you need not act. Auditors raise them where they see a weakness that has not yet caused a failure, or a practice simply better than yours - free intelligence, not criticism. Ignore one and that is fine; ignore a run of them that later surface as nonconformities, and you erode the auditor's confidence in your judgement.

Remote, on-site, or hybrid. Remote and hybrid audits are now routine, with accreditation-body guidance on using video and screen-sharing for some site time. The document-heavy half of an audit travels well to a screen - controlled documents, interviews, management-review and internal-audit records. What does not is anything physical: watching a process run, checking the workstation copy against the system, sampling calibration labels. So a hybrid audit does the documents remotely and keeps the visit for those checks. Remote is not the softer option: your evidence must be retrievable on screen in real time, and a fumbled screen-share signals how controlled your information really is.

The auditor's independence is the whole point: with no stake in passing you, their certificate is one a customer accepts instead of auditing you - one accredited certificate standing in for dozens of separate customer audits, and much of what makes certification commercially valuable.

Second-party (customer) audits: when a contract is on the line

A second-party audit is a customer auditing you - the one with the most immediate commercial edge. A prime contractor, a regulated buyer, or any customer for whom your work carries risk may audit you before awarding a contract (a pre-award or supplier-approval audit) and periodically during it (surveillance).

What is different about it. A certification auditor assesses you against the standard; a customer assesses you against their requirements - the standard usually included, plus whatever contract, regulatory, or sector conditions matter to them. Where certification samples across the whole standard, a customer's checklist is narrower and far deeper on the few things that touch their contract. Typically it digs into:

  • Traceability of what they buy - can you tie a delivered item back to its materials, lot or batch, and forward to everywhere it went, for the specific parts they order?
  • Control of the process they depend on - the special process at the heart of their product (heat treatment, welding, sterilisation, coding), examined far more closely than a general assessment would.
  • Flow-down of their requirements - the clauses they pass to you contractually, and evidence that you pass the relevant ones to your own subcontractors.
  • Change notification and escape handling - will you tell them before you change a material, process, or sub-supplier; and how would you run a recall or contain a nonconforming batch that has already reached them?
  • Their sector's own rules - a regulated buyer may layer its industry's expectations on top of ISO 9001: an aerospace customer's AS9100 flow-downs, a pharmaceutical buyer's GxP expectations, a medical-device maker's regulatory requirements.

These are the areas a certification audit touches only in passing; for the customer they are the whole point of the visit.

Contractual and tender impacts. This is where audits stop being a quality exercise and start being a commercial one:

  • Approved-supplier status. Many buyers maintain an approved-supplier list; a passed second-party audit is often the entry ticket, and a failed one keeps you off it. No place on the list, no invitation to quote.
  • Tender qualification. Public and large private tenders frequently make certification a pass/fail criterion - you either hold the accredited certificate for the right scope or you are screened out before your bid is read. A certificate that has lapsed, or whose scope does not cover the work, fails here just as never having had one does.
  • Contract conditions and remedies. Contracts increasingly write compliance in as a live obligation with teeth: maintain certification for the term, permit audits on notice, and close findings within agreed timescales - often a set window for majors and longer for minors, with evidence submitted for the customer to accept. Miss those and the remedies escalate: a corrective-action demand, then increased audit frequency or probation, then withheld orders or removal from the approved-supplier list, and - for persistent failure or a certificate left to lapse mid-contract - termination for breach. The same clauses usually make you flow equivalent obligations to your subcontractors, so a finding in your supply chain becomes one against you.
  • Reputational spillover. A customer who finds a serious problem in an audit does not just record a nonconformity; they revise their view of you as a supplier. Findings travel.

The through-line is that audit results are not filed and forgotten - they gate access to markets and shape the terms you are offered.

Making every audit easier: the same evidence, ready on demand

All three audits ask for the same underlying thing: current, retrievable evidence that your system does what it claims. Each auditor - internal, certification, or customer - wants the same records: controlled documents, closed-out nonconformities, completed internal audits, management reviews. The organisations that dread audits assemble that evidence from scratch each time; the ones who take them in stride keep it continuously, as a by-product of working.

This is the practical case for a quality management system. ComplyTrain's QMS holds the documents, the audit programme, the findings and their corrective actions, and the management-review record in one place, organised by the standard's requirements - so preparing for any of the three audit types is a matter of retrieval rather than reconstruction. The ISO 9001 page details the requirements those audits assess.


Audit season shouldn't mean a fire drill. Book a demo and we'll show you how ComplyTrain keeps internal, certification, and customer audits fed from the same always-current evidence - so a finding is the exception, not the norm.