What Is a First Party Audit?
A first party audit is an internal audit conducted by an organisation on itself. The organisation is both the audit client and the auditee. You plan it, you resource it, you conduct it, and you act on the findings. No external auditor walks through the door. No certification body is involved. It is entirely self directed.
On this page
The term comes from the three party audit framework defined in ISO 19011 and widely used across ISO standards. First party audits are internal. Second party audits are conducted on suppliers or external providers. Third party audits are conducted by independent certification bodies or regulators. Each serves a different purpose, and none of them replaces the others.
First party audits are required under ISO 9001, ISO 14001, and ISO 45001. They are not optional extras. They are a core part of what the standards call the performance evaluation cycle, sitting alongside monitoring, measurement, and management review. If you are running a certified management system, you are expected to be running a programme of first party audits throughout the year.
Why First Party Audits Exist
The purpose of a first party audit is straightforward: to give the organisation an honest, evidence based view of whether its management system is working as intended. That means checking conformity with the requirements of the relevant standard, conformity with the organisation's own documented procedures, and whether the system is actually producing the outcomes it was designed to produce.
That last point is often missed. Many internal audit programmes stop at conformity. They check whether documents exist, whether records are complete, whether procedures are being followed. That is necessary, but it is not sufficient. The standard also expects you to evaluate effectiveness. Is the system actually working? Are processes delivering the results the organisation needs?
First party audits also serve a practical preparation function. If your organisation holds ISO certification, a well run internal audit programme is your best preparation for the certification body's surveillance and recertification audits. Auditors from certification bodies look at your internal audit records. They want to see that your programme is active, that findings are being raised, that corrective actions are being closed. A clean internal audit history with no findings at all is not reassuring. It usually suggests the audits are not probing deeply enough.
Exemplar Global Recognised Training ProviderRTP No. 310970The Legal and Standard Requirements Behind First Party Audits
The requirement for first party audits appears in Clause 9.2 of ISO 9001, ISO 14001, and ISO 45001. The wording is consistent across all three standards because they share the harmonised structure. The organisation must conduct internal audits at planned intervals to provide information on whether the management system conforms to the organisation's own requirements and the requirements of the standard, and whether it is effectively implemented and maintained.
Clause 9.2 also requires the organisation to plan, establish, implement, and maintain an audit programme. That programme must consider the importance of the processes concerned, changes affecting the organisation, and the results of previous audits. In plain terms, your audit programme should be risk based. Higher risk processes and areas with previous nonconformities should receive more audit attention.
For a more detailed breakdown of what Clause 9.2 actually requires, the article on ISO 9001 Clause 9.2 internal audit requirements covers this thoroughly. The same logic applies across ISO 14001 and ISO 45001.
The standards do not prescribe how many audits you must conduct or how long each one must take. That is a deliberate design choice. The frequency and scope of your audit programme should reflect the size and complexity of your organisation, the risks involved, and the maturity of your system. A small business with a simple QMS might run four internal audits per year. A large manufacturing operation with an integrated management system might run twenty or more.
Who Conducts a First Party Audit?
This is where many organisations get themselves into trouble. The person conducting a first party audit must be impartial and objective with respect to the activity being audited. That is a requirement, not a suggestion. You cannot audit your own work. If you are the quality manager responsible for document control, you cannot audit document control.
This does not mean you need to hire an external auditor to conduct your internal audits. It means you need to think carefully about who audits what. In larger organisations, this is usually managed by having people audit functions outside their own area. A production supervisor audits the purchasing process. The procurement manager audits the warehouse. Cross functional auditing like this satisfies the independence requirement and has the added benefit of building broader understanding of the system across the team.
In smaller organisations where the quality manager is responsible for nearly everything, the independence requirement becomes harder to satisfy. Options include bringing in a contracted internal auditor, using a consultant to conduct the audits, or having a senior manager from another part of the business audit specific processes. What you cannot do is have someone sign off on an audit of their own work and call it independent.
The competence of internal auditors also matters. ISO standards require that internal auditors be competent to conduct audits. That means having the knowledge and skills to plan and conduct an audit, gather and evaluate evidence, and report findings clearly. Formal training is the most reliable way to demonstrate that competence. An ISO internal auditor course gives auditors the structured foundation they need to conduct first party audits that are credible and useful.
How to Plan a First Party Audit
Planning is where most first party audits succeed or fail. A poorly planned audit produces superficial findings. A well planned audit produces genuine insight.
Build a Risk Based Audit Programme
Start at the programme level, not the individual audit level. Map out the processes and areas that need to be audited across the year. Consider which processes carry the most risk, which have had issues in the past, and which have changed recently. Allocate more audit time and frequency to high risk areas. This is what the standards mean by a risk based approach to audit scheduling.
Your programme should cover all significant elements of the management system over the certification cycle, but it does not need to audit everything with equal frequency. A process that has been running smoothly for three years with no nonconformities might be audited once per year. A process that had a major nonconformity six months ago might be audited every quarter until you are confident the corrective action has taken hold.
Define Clear Audit Objectives and Scope
Before each individual audit, define what you are trying to achieve. What processes are in scope? What standard clauses apply? What specific questions or risks are you investigating? Vague objectives produce vague audits. If your objective is simply to check conformity with ISO 9001, you have not planned an audit. You have planned a general wander through the management system.
A better objective might be: to verify that the customer complaint handling process is operating in accordance with the documented procedure and is producing effective corrective actions. That gives the auditor a clear focus and makes it easier to assess whether the audit achieved anything useful.
Prepare Your Checklist and Review Prior Records
Before the audit, review relevant documents, previous audit findings, corrective action records, and any complaints or incidents related to the area being audited. A checklist is a useful tool for ensuring coverage, but it should be a starting point, not a script. The best auditors use their checklist to make sure they have not missed anything, then follow the evidence wherever it leads.
How to Conduct a First Party Audit
The conduct phase follows a consistent structure regardless of the standard being audited or the process in scope.
Opening Meeting
Start with a brief opening meeting. Even for a small internal audit, this matters. It confirms the scope and objectives, explains how the audit will be conducted, and sets expectations. It also signals to the auditee that this is a structured, professional activity, not an informal chat or a fault finding exercise.
Gathering Evidence
Audit evidence comes from three main sources: document and record review, interviews with personnel, and direct observation of activities and conditions. Good internal auditors use all three. Do not rely solely on documents. Talk to the people doing the work. Watch processes in action where you can. The gap between what the procedure says and what actually happens on the floor is often where the most valuable findings sit.
Ask open questions. Give people space to explain what they do and why. Follow up on anything that does not quite add up. If a record shows a step was completed but the person you are interviewing cannot explain how that step is done, that is worth pursuing. Evidence should be objective, verifiable, and sufficient to support your conclusions.
Closing Meeting
Conclude the audit with a closing meeting where you present your findings. Be clear about what you found, what evidence it is based on, and how you have classified it. If you have raised a nonconformity, explain the requirement that has not been met and the evidence that supports the finding. Give the auditee the opportunity to respond. Disagreements about findings should be noted, not suppressed.
Recording and Reporting First Party Audit Findings
The audit report is the formal output of a first party audit. It does not need to be long, but it does need to be clear. A useful internal audit report includes the audit scope and objectives, the date and auditor, a summary of what was reviewed, the findings raised (classified as nonconformities, observations, or opportunities for improvement), and a conclusion on the effectiveness of the audited area.
Nonconformities raised in a first party audit require corrective action. The responsible area must identify the root cause, implement a correction, and take action to prevent recurrence. The auditor or audit programme manager should verify that corrective actions have been completed and were effective. This follow up step is where many internal audit programmes fall short. Raising a finding and then never checking whether it was properly resolved is not an effective audit programme.
Common Mistakes in First Party Audits
After conducting hundreds of external certification audits, the same internal audit weaknesses appear repeatedly.
- Audits that only check documents. If the audit consists entirely of reviewing records and ticking boxes, it is not probing the system. Get out of the office and talk to people.
- Findings that are too vague to act on. A finding that says document control needs improvement is useless. A finding that identifies a specific document that lacks version control, with the record as evidence, gives the corrective action owner something to work with.
- No follow up on corrective actions. Raising findings and filing the report without verifying closure turns the audit programme into a paperwork exercise.
- Auditing the same low risk areas every time. If your audit programme keeps auditing the same safe, easy areas while ignoring higher risk processes, you are not meeting the risk based intent of the standard.
- Auditors who lack training. Enthusiasm is not the same as competence. Internal auditors need to understand audit methodology, the relevant standard, and how to gather and evaluate evidence objectively.
Exemplar Global Recognised Training ProviderRTP No. 310970First Party Audits Versus Other Audit Types
It is worth being clear about how first party audits relate to the other audit types your organisation might encounter.
A second party audit is conducted by your organisation on an external provider, such as a key supplier. You are the auditor, and the supplier is the auditee. This is a different purpose and a different relationship to a first party audit, even though your own team is conducting both.
A third party audit is conducted by an independent certification body to assess conformity with a standard for the purpose of granting or maintaining certification. Your first party audit programme feeds directly into this. Certification body auditors will review your internal audit records, check that your programme is active and risk based, and look at how you have handled corrective actions from internal findings.
The three audit types are complementary. A strong first party audit programme makes your organisation better prepared for second and third party scrutiny, and it produces genuine improvements in the management system rather than simply maintaining certification compliance.
Building Auditor Competence for First Party Audits
The most common gap in internal audit programmes is not a lack of resources or time. It is a lack of trained auditors. People are assigned to conduct internal audits without any formal training in audit methodology, and the result is audits that do not probe deeply enough, findings that are poorly written, and corrective actions that do not address root causes.
Investing in formal internal auditor training pays for itself quickly. Trained auditors conduct better audits, write clearer findings, and give the organisation more confidence in the results. They also demonstrate auditor competence in a way that satisfies certification body expectations.
If you are looking to build or refresh your internal audit capability, Audit Workshop offers practical internal auditor training for ISO 9001, ISO 14001, and ISO 45001 at both internal auditor and lead auditor levels. The courses are delivered by practising auditors with real certification audit experience, so the content reflects what actually happens in audits rather than abstract theory. You can explore the differences between internal and certification audits to understand how your first party programme fits into the broader certification picture, and then choose the training level that matches where you are in your auditing journey.













