What Is a Second Party Audit?
A second party audit is an audit conducted by one organisation on another organisation that has a direct commercial or contractual relationship with it. In plain terms, it is when you audit your supplier, subcontractor, or service provider on your own behalf.
On this page
The term comes from the three party model used across ISO auditing. First party audits are internal audits you conduct on your own organisation. Second party audits are conducted on an external party you have a relationship with. Third party audits are conducted by independent certification bodies for the purpose of issuing or maintaining ISO certification.
Second party audits sit in an important middle ground. They are not the internal self assessment of a first party audit, and they are not the formal, accredited certification process of a third party audit. They are a practical tool for managing supplier risk, verifying contractual compliance, and building confidence in the organisations you depend on to deliver your products and services.
If you are a Quality Manager, HSE Manager, or Environmental Manager with suppliers in your scope, understanding how second party audits work is not optional. It is a core competency.
How Second Party Audits Differ From First and Third Party Audits
Understanding the three audit types helps you position second party audits correctly in your overall assurance programme.
First Party Audits
A first party audit is an internal audit. You audit your own organisation against your own management system requirements, ISO standards, or internal procedures. The purpose is self improvement and readiness. The auditor is employed by or contracted to the organisation being audited.
Second Party Audits
A second party audit is conducted by you, or someone acting on your behalf, on a supplier or external provider. The audit criteria might include your own contractual requirements, relevant ISO standards, regulatory requirements, or a combination. The relationship between auditor and auditee is a commercial one. You are the customer assessing a supplier.
Third Party Audits
A third party audit is conducted by an independent, accredited certification body. The auditor has no commercial relationship with the organisation being audited. The outcome is a formal certification decision. Third party audits are the only type that result in ISO certification.
The key distinction for second party audits is the relationship. You have skin in the game. The outcome of the audit affects your business directly. That commercial context changes the dynamic in ways that internal auditors and certification auditors do not always experience.
Exemplar Global Recognised Training ProviderRTP No. 310970When Should You Use a Second Party Audit?
Not every supplier needs a second party audit. Using them indiscriminately wastes resources and damages supplier relationships. The question is when they add genuine value.
High Risk Suppliers
If a supplier failure would directly affect your product quality, safety outcomes, or environmental performance, that supplier warrants closer scrutiny. A subcontractor who installs safety critical components, a chemical supplier whose products affect your environmental compliance, or a labour hire company whose workers carry out high risk activities on your site are all candidates for second party auditing.
New Supplier Onboarding
Before you commit to a new supplier relationship, particularly for critical inputs, a second party audit gives you direct evidence of their capability. Questionnaires and supplier self assessments have their place, but they cannot substitute for actually observing a supplier's processes, talking to their people, and reviewing their records.
Supplier Performance Problems
If a supplier is generating recurring nonconformities, delivery failures, or quality escapes, a second party audit allows you to investigate the root cause at the source. Rather than managing the symptom at your end, you go upstream and look at the system that produced the problem.
Contractual or Regulatory Requirement
Some contracts, particularly in defence, construction, government supply, and food manufacturing, require buyers to conduct periodic second party audits as part of supplier qualification or ongoing approval. In these cases, the audit is not discretionary. It is a compliance obligation.
ISO 9001 Clause 8.4 Context
ISO 9001:2015 Clause 8.4 requires organisations to control externally provided processes, products, and services. The type and extent of control depends on the potential impact on the organisation's ability to consistently meet customer and regulatory requirements. Second party audits are one of the most effective controls available for high impact external providers. If you want to understand how this clause shapes your supplier management obligations, the article on ISO 9001 Clause 8.4: Managing Outsourced Processes and Suppliers covers it in detail.
Who Conducts Second Party Audits?
Second party audits can be conducted by your own staff, or by an external auditor acting on your behalf. Both approaches have trade-offs.
Internal Staff
Using your own quality, HSE, or procurement staff keeps costs down and ensures the auditor understands your specific requirements and context. The risk is that your staff may lack formal auditor training, which can lead to audits that are superficial, inconsistent, or legally problematic if findings become disputed.
Contracted Auditors
Engaging a qualified external auditor to conduct second party audits on your behalf brings discipline and credibility. This is common in industries where the audit findings carry significant weight, such as aerospace, pharmaceuticals, and major construction. The auditor acts as your agent, and the audit report belongs to you.
Regardless of who conducts the audit, the auditor should have relevant competence. That means understanding the standard or criteria being audited against, having some familiarity with the industry or process being assessed, and having the practical auditing skills to gather evidence, identify gaps, and communicate findings clearly.
If your team is conducting second party audits without formal training, that is a gap worth addressing. The skills involved, such as planning, interviewing, evidence gathering, and report writing, are not intuitive. They need to be learned.
What Do Second Party Audits Cover?
The scope and criteria of a second party audit depend on what you need to verify. Common areas include:
- Quality management processes: Does the supplier have documented procedures? Are they followed? Is there evidence of nonconformity management and corrective action?
- Product or service conformity: Are the supplier's outputs meeting the specifications you require? Are inspection and testing processes in place?
- Competence and training: Are the people doing the work qualified and trained? Are records maintained?
- Documented information: Are records retained in a way that provides traceability? Can the supplier demonstrate conformity on request?
- Subcontractor control: If your supplier uses their own subcontractors, how do they manage that chain? This is particularly relevant in construction and services.
- Legal and regulatory compliance: Are there applicable environmental, safety, or product safety obligations that the supplier must meet? Are they meeting them?
- Corrective action history: Have previous issues been addressed? Is there evidence of genuine improvement or just paper fixes?
The audit criteria should be defined before the audit begins. This might be your own supplier requirements specification, a relevant ISO standard such as ISO 9001 or ISO 45001, a regulatory framework, or a combination. Vague criteria produce vague audits.
How to Plan and Conduct a Second Party Audit
The process for a second party audit follows the same general structure as any audit: plan, conduct, report, and follow up. The specifics differ in a few important ways.
Step 1: Define the Purpose and Scope
Be clear about why you are conducting the audit. Is it routine assurance, onboarding due diligence, or a response to a specific problem? The purpose shapes the scope. A focused audit investigating a specific quality escape is different from a broad capability assessment of a new supplier.
Step 2: Notify the Supplier and Agree on Logistics
Second party audits are almost always announced in advance. Surprise audits are rare in commercial relationships and can damage trust. Notify the supplier with enough lead time for them to prepare. Agree on the date, location, duration, and the processes or areas you intend to cover. Share the audit criteria so there are no surprises about what you will be looking at.
Step 3: Prepare Your Checklist and Document Review
Before arriving on site, request relevant documents from the supplier. This might include their quality manual, procedures for key processes, recent internal audit results, corrective action records, and any previous second party audit reports. Review these before the audit. This saves time on site and helps you identify areas to probe further.
Step 4: Conduct the On Site Audit
Open the audit with a brief meeting that confirms scope, objectives, and logistics. Then move through the agreed areas using a combination of document review, interviews, and observation. Do not spend the entire audit in a meeting room. Walk the floor. Watch the process. Talk to the workers doing the work, not just the manager presenting the system.
Gather objective evidence. If a procedure says that incoming materials are inspected before use, ask to see the inspection records. If a safety procedure requires workers to be trained before operating equipment, ask to see the training records and then ask the operator what they do if the equipment malfunctions. The answer should match the procedure.
Step 5: Hold a Closing Meeting
At the end of the audit, present your findings to the supplier's management. Be clear about what you found, what evidence supports each finding, and how you have classified it. This is not the time for ambiguity. If there is a nonconformity, say so directly and explain why. If there are positive observations, mention those too. The closing meeting sets the tone for the corrective action process that follows.
Step 6: Issue the Audit Report
Write a clear, factual report that documents what was audited, what evidence was reviewed, and what findings were raised. Each finding should reference the specific requirement it relates to and the evidence that supports it. The report is your organisation's record of the audit. It should be complete enough that someone who was not present can understand exactly what was found and why.
Step 7: Follow Up on Corrective Actions
Raising findings without following up on them is a waste of everyone's time. Agree on a timeframe for the supplier to respond with a corrective action plan. Review the plan to confirm it addresses the root cause, not just the symptom. Close the finding only when you have objective evidence that the corrective action has been implemented and is effective.
Common Mistakes in Second Party Audits
Second party audits are often conducted by people who have not had formal auditor training. That leads to predictable problems.
Auditing to the Supplier's System, Not Your Requirements
A common mistake is accepting whatever system the supplier has in place without checking whether it actually meets your requirements. The supplier may have ISO 9001 certification, but that does not mean their processes meet your specific contractual or technical requirements. Third party certification tells you the supplier has a management system. It does not tell you whether that system is configured to deliver what you need.
Staying in the Meeting Room
Audits conducted entirely through document review and management presentations miss the reality of what is happening on the floor. The procedure might be perfect. The practice might be completely different. You need to observe the process, not just read about it.
Failing to Define Criteria in Advance
If you have not defined what you are auditing against, you cannot raise a defensible finding. Vague criteria lead to vague audits and disputed findings. Before the audit, be explicit about what requirements apply and where they come from.
Treating Findings as a Negotiation
Some auditors soften findings to avoid damaging the supplier relationship. This defeats the purpose. If there is a nonconformity, it needs to be documented accurately. The relationship is better served by honest findings and genuine corrective action than by papering over problems that will resurface later.
Second Party Audits and ISO 19011
ISO 19011 is the international guideline for auditing management systems. It applies to all audit types, including second party audits. The 2026 edition of ISO 19011 includes expanded guidance specifically on second party auditing and supply chain contexts, reflecting how central supplier auditing has become in modern quality and safety management.
The principles in ISO 19011, including integrity, fair presentation, due professional care, confidentiality, independence, and evidence based conclusions, apply equally to second party audits. The fact that you have a commercial relationship with the auditee does not reduce your obligation to audit objectively. In some ways, it increases it, because the temptation to go easy on a valued supplier is real.
If you want to understand how the auditing guidelines shape practice across all audit types, the article on How the ISO 19011 Guidelines Shape Modern Audit Practice is worth reading alongside this one.
Exemplar Global Recognised Training ProviderRTP No. 310970Building a Second Party Audit Programme
Ad hoc supplier audits have limited value. A structured second party audit programme gives you consistent coverage, risk based prioritisation, and a defensible record of supplier oversight.
A basic programme should include:
- A register of suppliers subject to second party auditing, with risk ratings that drive audit frequency
- Annual audit planning that allocates audit resources to the highest risk suppliers first
- Standard audit criteria and checklists for common supplier types
- A consistent report format so findings are comparable across suppliers and over time
- A corrective action tracking process with defined escalation for overdue or ineffective responses
- A review mechanism that feeds supplier audit results into your own management review and supplier evaluation processes
For organisations managing large or complex supply chains, the second party audit programme becomes a significant undertaking. It requires trained auditors, management commitment, and a clear process for acting on findings.
How Training Supports Second Party Auditing
If your team is conducting second party audits, they need auditor training. Not just awareness of what an audit is, but practical skills in planning, interviewing, evidence gathering, nonconformity writing, and report writing.
An internal auditor course gives your staff the foundation they need to conduct credible second party audits. A lead auditor course goes further, covering audit programme management and the skills needed to lead audit teams across complex supplier engagements.
The question of which level to start at depends on your role and what you need to do. If you are responsible for managing your organisation's supplier audit programme, you may want to look at how ISO Lead Auditor vs Internal Auditor: Which Course Do You Need? breaks down the decision.
At Audit Workshop, training is built around real audit practice. Courses cover ISO 9001, ISO 14001, and ISO 45001 at Foundation, Internal Auditor, and Lead Auditor levels. If your team is conducting or planning to conduct second party audits, the Internal Auditor or Lead Auditor courses will give them the skills to do it properly, not just go through the motions. You can explore the options at auditworkshop.com.













