If you are new to ISO auditing, one of the first things you need to understand is that not all audits are the same. The phrase types of audits refers to a formal classification system that tells you who is conducting the audit, who they are auditing, and what the relationship is between them. ISO 19011 uses the terms first party, second party, and third party to describe these three categories. Each type has a different purpose, a different level of independence, and a different set of expectations. Getting clear on these distinctions early will help you understand where your role fits, what is expected of you, and how to develop your auditing career in the right direction.
On this page
Why the Classification Matters
The classification of audit types is not just academic. It shapes how an audit is planned, who can conduct it, what criteria apply, and what the output is used for. A first party audit is an internal check. A second party audit is a commercial relationship check. A third party audit is an independent verification that carries formal consequences, including whether or not a certificate is granted or maintained.
Understanding the differences also helps you choose the right training. Someone who only needs to run internal audits for their organisation has different training needs from someone who wants to audit suppliers or work for a certification body. The ISO Lead Auditor vs Internal Auditor course comparison covers this in detail, but the foundation of that decision starts here, with understanding what type of audit you will actually be conducting.
Exemplar Global Recognised Training ProviderRTP No. 310970First Party Audits: Auditing Yourself
A first party audit is an internal audit. The organisation audits itself. The auditors are employees of the organisation, or contractors engaged by the organisation to act on its behalf. The purpose is to check whether the organisation is conforming to its own requirements, to the requirements of the relevant ISO standard, or to both.
Under ISO 9001 Clause 9.2, organisations are required to conduct internal audits at planned intervals. The same requirement exists in ISO 14001 and ISO 45001. These clauses do not give organisations a choice. If you are certified to any of these standards, you must have a functioning internal audit programme.
What First Party Audits Are Used For
First party audits serve several practical purposes. They help organisations identify nonconformities before an external auditor finds them. They provide evidence of continual improvement. They test whether documented processes are being followed in practice. They also provide input to the management review process, which is another mandatory requirement under the ISO standards.
In a well run organisation, first party audits are not a compliance exercise. They are a genuine tool for finding problems and fixing them before they affect customers, workers, or the environment. The best internal auditors treat their own organisation with the same scrutiny they would apply to any other site.
Who Can Conduct a First Party Audit
The auditor must be independent of the activity being audited. This is a requirement under ISO 9001 Clause 9.2 and is reinforced by ISO 19011. You cannot audit your own work. But you can audit another department or another process within the same organisation. In a small business, this can be genuinely difficult to manage, and it is one of the reasons some organisations outsource their internal audit function.
The competence requirements for internal auditors are real. ISO 19011 sets out the knowledge and skills that auditors need, and organisations are expected to be able to demonstrate that their internal auditors are competent. A training course that leads to a recognised qualification is the most straightforward way to demonstrate this.
Second Party Audits: Auditing Your Supply Chain
A second party audit is conducted by one organisation on another, where a commercial or contractual relationship exists. The most common example is a customer auditing a supplier. The organisation conducting the audit has a direct interest in the outcome, because the supplier provides goods or services that affect the auditing organisation's own quality, safety, or environmental performance.
Second party audits are not required by ISO standards in the same way that internal audits are. However, ISO 9001 Clause 8.4 requires organisations to control externally provided processes, products, and services. For many organisations, conducting supplier audits is the most effective way to meet this requirement, particularly for high risk or critical suppliers.
Common Scenarios for Second Party Audits
Second party audits come up regularly in industries where supply chain risk is significant. A construction company might audit a subcontractor's safety management system before allowing them on site. A food manufacturer might audit a raw material supplier's hygiene controls. A mining company might audit a labour hire agency's competency management processes.
The audit criteria for a second party audit are typically set by the auditing organisation. They might be based on the relevant ISO standard, on the customer's own internal requirements, or on a combination of both. The auditing organisation decides the scope, the criteria, and the level of formality.
Independence in Second Party Audits
Second party auditors are not independent in the way a third party auditor is. They work for, or on behalf of, the organisation with the commercial interest. This is acceptable, but it does mean that the objectivity and professionalism of the auditor become even more important. A second party auditor who is too close to the commercial relationship, or who allows business pressures to influence their findings, will produce an audit that does not serve anyone well.
For this reason, many organisations that conduct regular supplier audits invest in formal auditor training for their procurement or quality teams. Knowing how to gather evidence, write findings, and conduct an audit interview properly makes a significant difference to the quality of the output.
Third Party Audits: Independent External Verification
A third party audit is conducted by an independent body that has no commercial interest in the outcome. The most common form of third party audit in the ISO world is a certification audit, conducted by an accredited certification body. When a certification body audits your organisation against ISO 9001, ISO 14001, or ISO 45001, that is a third party audit.
Other forms of third party audits include regulatory audits conducted by government agencies, audits conducted by industry bodies, and audits conducted as part of a statutory compliance scheme. What they all have in common is that the auditor is independent of both the audited organisation and any commercial party with an interest in the outcome.
The Certification Audit Process
For most organisations, the third party audit they are most familiar with is the certification audit. This typically involves two stages. Stage 1 is a readiness review, where the auditor checks whether the organisation's documentation and management system are sufficiently developed to proceed to a full audit. Stage 2 is the on site assessment, where the auditor gathers evidence that the system is implemented and effective.
If the organisation passes the Stage 2 audit, the certification body issues a certificate that is valid for three years, subject to annual surveillance audits. At the end of the three year cycle, a recertification audit is conducted. Throughout this process, the certification body must be accredited by a recognised accreditation body, such as JAS ANZ in Australia. This accreditation is what gives the certificate its credibility in the market.
Who Conducts Third Party Audits
Third party auditors work for certification bodies. They are typically required to hold a recognised auditor qualification, such as those offered through Exemplar Global or IRCA, and to have relevant industry experience. The requirements vary depending on the certification body and the standard being audited.
If you want to work as a third party auditor, you will need to complete a Lead Auditor course at a minimum. Most certification bodies also require you to complete a period of witness auditing under supervision before you can conduct certification audits independently. The pathway is structured but achievable, and the demand for qualified auditors in Australia is steady.
How the Three Types Compare in Practice
It helps to see these three types side by side, because the differences in purpose, independence, and consequence are significant.
- First party audits are internal, conducted by or on behalf of the organisation itself, primarily for improvement and compliance verification. The output is an internal audit report that feeds into the management review and corrective action process.
- Second party audits are external, conducted by a customer or interested party on a supplier or partner. The output influences purchasing decisions, contract terms, and supplier approval status.
- Third party audits are independent, conducted by accredited certification bodies or regulatory agencies. The output is a formal certification decision or regulatory determination with significant commercial and legal consequences.
The level of rigour expected increases as you move from first to third party. A first party audit conducted by a well trained internal auditor is valuable, but it does not carry the same weight as a third party certification audit conducted by an accredited body. This is not a criticism of internal audits. It is simply the nature of independence and its role in assurance.
The Role of ISO 19011 Across All Three Types
ISO 19011 is the international guideline for auditing management systems. It applies to first and second party audits directly, and it informs best practice for third party audits as well. The 2026 edition of ISO 19011 introduced updated guidance on topics including remote auditing, risk based audit programme planning, and the competence requirements for auditors working with emerging technologies.
Whether you are an internal auditor running your first programme or a lead auditor managing a team on a complex certification audit, ISO 19011 provides the framework for how audits should be planned, conducted, and reported. Understanding this guideline is part of being a competent auditor at any level.
Choosing the Right Training for Each Audit Type
Your training needs depend directly on which type of auditing you intend to do. This is a practical decision, not just a theoretical one.
For First Party Auditing
If your role involves running internal audits within your own organisation, an Internal Auditor course is the appropriate starting point. These courses cover audit planning, evidence gathering, interview techniques, and nonconformity reporting in the context of internal audit practice. You do not need a Lead Auditor qualification to conduct first party audits, though it will certainly improve your capability.
For Second Party Auditing
If you are auditing suppliers on behalf of your organisation, an Internal Auditor course will give you the core skills, but a Lead Auditor course will give you a stronger foundation in audit management, criteria setting, and findings communication. Many organisations that run active supplier audit programmes invest in Lead Auditor training for their procurement and quality teams precisely because the skills transfer directly.
For Third Party Auditing
If you want to work as a certification auditor, you need a Lead Auditor qualification, relevant industry experience, and a pathway through a certification body's own auditor development programme. The Lead Auditor course is the entry point, not the finish line. But it is an essential step, and the quality of that training matters. A course recognised by Exemplar Global or IRCA gives you a qualification that certification bodies will recognise when you apply.
For a detailed look at how these career levels build on each other, the ISO auditor career path from internal auditor to lead auditor is worth reading before you decide which course to take.
Exemplar Global Recognised Training ProviderRTP No. 310970A Note on Combined and Integrated Audits
In practice, many audits do not fit neatly into a single category. A certification body might conduct a combined audit covering ISO 9001, ISO 14001, and ISO 45001 simultaneously. An organisation might conduct an internal audit that also covers supplier performance against contracted requirements. These hybrid approaches are common, and ISO 19011 provides guidance on how to manage them.
The key point is that the classification of first, second, and third party refers to the relationship between the auditor and the auditee, not to the number of standards being audited or the format of the audit. A combined audit covering three standards is still a third party audit if it is conducted by an accredited certification body.
Practical Takeaways for Quality and HSE Managers
If you are a Quality Manager, HSE Manager, or Environmental Manager reading this, here is what this means for your day to day work.
- Your internal audit programme is a first party activity. You are responsible for ensuring it is planned, resourced, and conducted by competent auditors. ISO 9001 Clause 9.2, ISO 14001 Clause 9.2, and ISO 45001 Clause 9.2 all make this a mandatory requirement.
- If you have a supply chain, you may need a second party audit programme. ISO 9001 Clause 8.4 requires you to control external providers, and for high risk suppliers, auditing is often the most effective control.
- Your certification audit is a third party activity. You do not control it, but you can prepare for it. Understanding what a third party auditor is looking for, and how they gather evidence, will help you present your system effectively.
- Training your team in auditing skills improves performance across all three types. An internal auditor who understands how a certification auditor thinks will write better audit reports, raise more useful findings, and prepare the organisation more effectively for external scrutiny.
Audit Workshop offers training at Foundation, Internal Auditor, and Lead Auditor levels across ISO 9001, ISO 14001, and ISO 45001. If you are trying to work out which level is right for your situation, the Foundation vs Internal Auditor course guide will help you make that decision with confidence. Courses are available live and self paced, and all are delivered by a practitioner with over 500 external certification audits behind them.













