Exemplar Global Certified Courses from USD 99. Ending Soon!

Third Party Audits Explained: What They Are, How They Work, and What to Expect

AW

Team @ Audit Workshop

13 min read
Third Party Audits Explained: What They Are, How They Work, and What to Expect

What Is a Third Party Audit?

A third party audit is an independent assessment of an organisation's management system, product, or service conducted by an external body that has no direct relationship with either the organisation being audited or its customers. The auditing body is completely independent of both parties, which is what makes it a third party arrangement.

In practical terms, this means a certification body such as SAI Global, Bureau Veritas, SGS, or LRQA sends a qualified lead auditor to assess whether your management system conforms to the requirements of a specific ISO standard. If it does, the certification body issues a certificate. If it does not, you receive nonconformities that must be addressed before certification is granted or maintained.

Third party audits sit at the top of the audit hierarchy. First party audits are internal audits you run on yourself. Second party audits are audits conducted by a customer or interested party on a supplier. Third party audits are conducted by an independent body with formal accreditation to certify organisations against recognised standards.

For anyone working in quality, environmental, or safety management, understanding how third party audits work is not optional. It is fundamental. Whether you are preparing your organisation for certification, maintaining an existing certificate, or building a career as an auditor, this is the audit type that carries the most external weight.

The Purpose of a Third Party Audit

The core purpose is independent verification. When a customer, regulator, or tender panel sees an ISO certificate, they are relying on the fact that an accredited, independent body has assessed the organisation and found its management system to be conforming. The certificate is only credible because the auditor had no stake in the outcome.

This is fundamentally different from an internal audit, where the organisation is assessing itself, or a second party audit, where a customer is assessing a supplier with a commercial interest in the result. Third party audits remove that conflict of interest entirely.

Third party audits serve several practical purposes:

  • Granting initial ISO certification to organisations that have implemented a management system
  • Maintaining certification through annual or biannual surveillance audits
  • Renewing certification at the end of the three year certification cycle through recertification audits
  • Providing independent assurance to customers, regulators, and other interested parties
  • Supporting tender requirements where ISO certification is a mandatory or scored criterion

In Australia, ISO certification is increasingly expected in government procurement, construction, mining, and healthcare sectors. Winning a contract often depends on holding a valid certificate. That certificate only exists because a third party auditor assessed and approved the management system behind it.

Who Conducts Third Party Audits?

Certification Bodies

Third party audits for ISO certification are conducted by certification bodies. These organisations employ or contract lead auditors who are qualified to assess management systems against specific ISO standards. Certification bodies must themselves be accredited by a recognised accreditation body to issue certificates that carry international recognition.

In Australia, the relevant accreditation body is JAS-ANZ (Joint Accreditation System of Australia and New Zealand). JAS-ANZ accredits certification bodies to operate under the requirements of ISO/IEC 17021, which governs how certification bodies must manage their audit processes, auditor competence, and impartiality.

When a certification body holds JAS-ANZ accreditation, its certificates are recognised internationally through the IAF (International Accreditation Forum) Multilateral Recognition Arrangement. This means an ISO 9001 certificate issued by a JAS-ANZ accredited body in Australia is recognised in over 100 countries. That international recognition is what gives the certificate real commercial value.

Regulatory and Scheme-Based Third Party Auditors

Not all third party audits are ISO certification audits. Third party auditing also occurs in regulated industries where independent assessment is required by law or by an industry scheme. Examples include:

  • NDIS audits conducted by approved quality auditors against the NDIS Practice Standards
  • Food safety audits conducted by approved auditors under HACCP-based schemes
  • Building certification by independent certifiers under state planning legislation
  • Financial audits conducted by registered company auditors under the Corporations Act

The common thread is independence. The auditing entity has no commercial relationship with the organisation being audited beyond the audit itself, and the results are reported to a third party such as a regulator, scheme owner, or accreditation body.

The Third Party Audit Process: Stage by Stage

For ISO certification audits, the third party audit process follows a structured sequence that is largely consistent across certification bodies. Understanding this sequence removes a lot of the anxiety that organisations feel before their first certification audit.

Stage 1 Audit: Document Review and Readiness Assessment

The Stage 1 audit is a preliminary assessment, usually conducted remotely or at the organisation's site, to determine whether the management system is sufficiently developed to proceed to the full certification audit. The auditor reviews the scope of the management system, key documented information such as the quality policy, objectives, and internal audit records, and assesses whether the organisation understands the requirements of the standard.

The Stage 1 is not a pass or fail event in the same way as Stage 2. Its purpose is to identify significant gaps that would prevent Stage 2 from being productive. If major gaps are found, the certification body will advise you to address them before Stage 2 proceeds. If the system looks ready, Stage 2 is scheduled.

Stage 2 Audit: On-Site Assessment

The Stage 2 audit is the main certification event. The auditor spends time on site interviewing personnel, observing processes, and reviewing records to verify that the management system is not only documented but actually implemented and effective. This is where conformity is assessed clause by clause against the requirements of the standard.

The auditor will raise nonconformities where evidence of conformance cannot be found. Nonconformities are classified as major or minor. A major nonconformity means the management system has failed to meet a fundamental requirement of the standard. A minor nonconformity means a requirement is partially met or a single isolated gap has been identified. Major nonconformities must be closed before a certificate is issued. Minor nonconformities are typically closed within an agreed timeframe after certification.

Surveillance Audits

Once certified, the organisation enters a three year certification cycle. Surveillance audits are conducted at least annually (in most cases) to verify that the management system continues to meet the standard's requirements. Surveillance audits do not cover the entire standard in one visit. They typically focus on specific areas, including any nonconformities raised in previous audits and any significant changes to the organisation.

Failing to address previous nonconformities, allowing the management system to deteriorate, or making significant changes without updating the system are the most common reasons organisations receive nonconformities at surveillance audits.

Recertification Audit

At the end of the three year cycle, the certification body conducts a recertification audit. This is a more comprehensive assessment that reviews the entire management system, similar in scope to the original Stage 2. If the system remains conforming, the certificate is renewed for another three years. If significant nonconformities are found, certification may be suspended until they are addressed.

What Third Party Auditors Actually Look For

Experienced auditors conducting third party audits are not looking to find fault for its own sake. They are trying to determine whether the management system is genuinely implemented and whether it is producing the outcomes the standard requires. That distinction matters.

A management system that looks perfect on paper but shows no evidence of implementation will fail a third party audit. Conversely, a system with some documentation gaps but clear evidence of real implementation and continual improvement is likely to receive minor nonconformities rather than major ones.

The areas that consistently attract scrutiny in third party audits include:

  • Internal audits: Are they being conducted to plan? Are the findings credible? Are nonconformities being closed?
  • Management review: Is top management genuinely engaged, or is the review a box-ticking exercise?
  • Objectives: Are quality, environmental, or safety objectives measurable, monitored, and linked to real performance data?
  • Corrective actions: Are root causes being identified and addressed, or are the same problems recurring?
  • Competence: Can the organisation demonstrate that people doing work affecting quality, environment, or safety have the required competence?
  • Legal and compliance obligations: For ISO 14001 and ISO 45001, can the organisation demonstrate it has identified its legal obligations and is meeting them?

If you want a detailed look at what auditors examine in a quality management system context, the article on what auditors look for in an ISO 9001 quality management system covers this in depth.

How Third Party Audits Differ From Internal and Second Party Audits

The three audit types serve different purposes and operate under different constraints. Confusing them leads to poor preparation and misaligned expectations.

An internal audit is conducted by the organisation on itself. Its purpose is to find problems before the certification body does and to drive continual improvement. The auditor is an employee or contractor working for the organisation. There is no external consequence if a nonconformity is found because the finding stays internal. The standard that governs internal audit requirements for ISO 9001 is Clause 9.2, and the audit must be conducted by someone who is independent of the work being audited, but that person can still be employed by the organisation.

A second party audit is conducted by a customer, a potential customer, or another interested party on a supplier or prospective supplier. The auditor works for the organisation commissioning the audit, not for an independent body. Second party audits are common in supply chains where customers need assurance that critical suppliers are meeting specific requirements. They carry commercial weight but do not result in independent certification.

A third party audit is conducted by an independent accredited body. The auditor works for the certification body, not for the organisation being audited or for any of its customers. The result is an independent certificate that carries credibility precisely because of that independence. The article on types of audits: first, second and third party provides a useful side-by-side comparison if you want to understand the distinctions more clearly.

Preparing Your Organisation for a Third Party Audit

The single biggest mistake organisations make when preparing for a third party audit is treating it as a documentation exercise. They spend weeks producing procedures and records specifically for the audit, then struggle when the auditor starts asking questions that reveal the system is not actually being used.

Genuine preparation means ensuring the management system is functioning as intended, not just documented. Here is what that looks like in practice:

Complete Your Internal Audit Programme

The certification body's auditor will ask to see internal audit records. If your internal audit programme has not been completed, or if the findings look superficial, this will raise questions about whether the system is being properly monitored. Complete your planned internal audits before the Stage 2, address the findings, and make sure the records are clear and credible.

Conduct a Management Review

Management review is a specific requirement under every major ISO standard. The auditor will want to see evidence that top management has reviewed the system, considered the required inputs, and made decisions about resources and improvements. A management review conducted the week before the audit with minutes that look rushed is obvious. Conduct genuine reviews and document them properly throughout the year.

Close Your Corrective Actions

Open corrective actions with no progress, or corrective actions that have been marked closed without evidence of root cause analysis and verification, are a common source of nonconformities at third party audits. Before your audit, review the status of all corrective actions and make sure the ones that should be closed actually are, with proper evidence.

Brief Your Team

The auditor will interview people at various levels of the organisation, not just the quality manager. Production supervisors, site managers, and front-line workers will be asked about the management system, their responsibilities, and how they handle nonconformities or incidents. Brief your team on what to expect, encourage honest answers, and make sure they understand their role in the system. For more detail on preparing people for this, the article on how to prepare your organisation for an external audit covers the key steps.

What Happens After a Third Party Audit

At the closing meeting, the auditor will present the findings. If nonconformities have been raised, the organisation will be given a timeframe to respond with corrective actions. The timeframe varies by certification body and by the severity of the finding, but major nonconformities typically require a response within 30 to 90 days.

For initial certification, the certification body reviews the corrective action responses before deciding whether to issue the certificate. For surveillance and recertification audits, the process is similar but the certificate may be suspended if major nonconformities are not closed within the agreed timeframe.

If the audit results in a recommendation for certification, the lead auditor's report goes to a technical reviewer at the certification body who is independent of the audit team. This review is a quality check on the audit itself, not a re-audit of the organisation. Once the review is complete and any corrective actions are accepted, the certificate is issued.

Third Party Auditing as a Career

Conducting third party audits is the work of lead auditors employed or contracted by certification bodies. It is one of the more demanding audit roles because you are making decisions with real commercial consequences for organisations. A major nonconformity you raise might delay someone's certification by months. A finding you miss might mean an organisation holds a certificate it has not genuinely earned.

To work as a third party auditor, you need lead auditor certification from a recognised scheme such as Exemplar Global or IRCA, a track record of audit experience, and technical competence in the industry sectors and standards you will be auditing. Most certification bodies also require witness audits to be completed before a new auditor is authorised to conduct third party audits independently.

The pathway from internal auditor to lead auditor to third party auditor is well established. If you are considering this career direction, the article on the ISO auditor career path from internal auditor to lead auditor outlines the steps involved.

At Audit Workshop, the Lead Auditor courses for ISO 9001, ISO 14001, and ISO 45001 are specifically designed to build the competence needed for third party auditing. The training covers audit planning, evidence gathering, nonconformity writing, and audit reporting in a way that reflects what certification body auditors actually do on site. If you are ready to move into third party auditing or simply want to understand what your certification body auditor is doing when they walk through your door, the courses at Audit Workshop are built for exactly that purpose.

Frequently Asked Questions

A first party audit is an internal audit conducted by the organisation on itself. A second party audit is conducted by a customer or interested party on a supplier. A third party audit is conducted by an independent accredited body, such as a certification body, with no commercial relationship to either the organisation being audited or its customers. Third party audits are the basis for ISO certification and carry the highest level of independent credibility.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.