Exemplar Global Certified Courses from USD 119. Ending Soon!

What Is a Compliance Audit? A Plain English Guide for Quality and Safety Professionals

AW

Team @ Audit Workshop

14 min read
What Is a Compliance Audit? A Plain English Guide for Quality and Safety Professionals

Defining a Compliance Audit

A compliance audit is a structured, independent examination of whether an organisation is meeting the requirements placed on it. Those requirements might come from a law or regulation, an ISO standard, a contract, an industry code, or the organisation's own internal policies. The auditor's job is to gather objective evidence and then form a conclusion about whether the organisation is doing what it is supposed to be doing.

That sounds simple, but in practice a compliance audit covers a lot of ground. Depending on the context, it might involve reviewing documented information, interviewing workers, observing operations on the floor, or testing whether a process produces the output it is supposed to produce. The common thread is that there is always a defined reference point, what auditors call the audit criteria, and the audit measures actual practice against that reference point.

If you work in quality, health and safety, environment, or information security, compliance audits are part of your professional landscape. Understanding what they are, how they differ from other types of audits, and what they actually look like in practice will make you better at managing them, conducting them, and responding to their findings.

What a Compliance Audit Is Checking Against

The audit criteria define the scope of a compliance audit. Different types of compliance audits use different criteria, and the criteria determine almost everything else about how the audit is designed and conducted.

Legal and Regulatory Requirements

Many compliance audits focus on whether an organisation is meeting its legal obligations. In an ISO 14001 environmental management system, for example, Clause 9.1.2 requires organisations to evaluate their compliance with environmental laws and other applicable requirements. An auditor conducting this type of compliance evaluation will look at the organisation's legal register, check whether all relevant legislation has been identified, and then test whether the organisation is actually meeting those obligations in practice.

In a workplace safety context, an auditor might check whether the organisation is meeting its duties under the Work Health and Safety Act, whether hazard identification processes are functioning, and whether incidents are being reported and investigated as the law requires.

ISO Standard Requirements

When an organisation is certified to an ISO standard, it has committed to meeting all the requirements of that standard. Certification audits, surveillance audits, and internal audits are all forms of compliance audit measured against the standard's clauses. If an internal auditor checks whether the management review is meeting the requirements of Clause 9.3 of ISO 9001, that is a compliance audit. If a certification body auditor checks whether the organisation's documented information meets Clause 7.5, that is also a compliance audit.

Contractual and Industry Requirements

Some compliance audits check conformance with contractual obligations. A construction company might be audited by a principal contractor to verify that it is meeting the quality and safety requirements set out in a subcontract. A supplier might be audited to check that it is meeting the product specification requirements in a supply agreement. These are second party compliance audits, conducted by or on behalf of the party that has an interest in the outcome.

Internal Policies and Procedures

Organisations can also audit compliance with their own internal requirements. If the quality manual says that all customer complaints must be acknowledged within 24 hours and investigated within five business days, an internal compliance audit can check whether that is actually happening. This type of audit is valuable because it tests whether the management system is being implemented as designed, not just whether it looks good on paper.

Types of Compliance Audits

Compliance audits can be classified in several ways, and understanding the distinctions helps you work out what role you are playing and what obligations you have.

First Party Compliance Audits

A first party audit is conducted by the organisation on itself. Internal audits under ISO standards are first party audits. The organisation uses its own auditors, or auditors it has engaged for the purpose, to check whether its own systems and practices are meeting the applicable requirements. The results are used internally to drive improvement and to prepare for external audits.

First party compliance audits are a requirement of most ISO management system standards. ISO 9001 Clause 9.2, ISO 14001 Clause 9.2, and ISO 45001 Clause 9.2 all require organisations to conduct internal audits at planned intervals. The purpose is to give the organisation an independent view of how well its system is functioning before an external auditor arrives.

Second Party Compliance Audits

A second party audit is conducted by one organisation on another, typically a customer auditing a supplier. These audits check whether the supplier is meeting the requirements set by the customer, whether those requirements are contractual, technical, or system based. Supplier audits are the most common form of second party compliance audit.

If you are a quality manager at a manufacturing business and you visit a critical supplier to check their quality management processes, you are conducting a second party compliance audit. The criteria might include your own supplier requirements, the relevant clauses of ISO 9001, or specific product specifications.

Third Party Compliance Audits

Third party audits are conducted by independent organisations with no direct interest in the outcome. Certification audits conducted by accredited certification bodies are third party compliance audits. Regulatory audits conducted by government agencies are also third party audits. The independence of the auditor is what gives third party audit conclusions their credibility.

When a certification body auditor tells you that your quality management system conforms to ISO 9001, they are giving you a third party compliance opinion. That opinion has market value because the auditor has no commercial interest in the outcome beyond conducting a competent audit.

How a Compliance Audit Differs From Other Types of Audits

The term audit is used loosely in business, and it helps to understand where compliance audits sit in relation to other audit types.

Compliance Audit vs Gap Analysis

A gap analysis is a pre audit assessment that identifies where an organisation's current practices fall short of a target state, usually a standard or regulatory requirement. It is typically conducted before certification or before implementing a management system. A gap analysis is not an audit in the formal sense because it does not produce audit findings with the same rigour or independence as a formal audit. It is a diagnostic tool. A compliance audit, by contrast, is a formal examination that produces findings, conclusions, and a formal report. Understanding what a gap analysis is and how it differs from a formal audit is useful context for anyone preparing for certification.

Compliance Audit vs Management Review

A management review is a leadership activity where top management evaluates the performance of the management system and makes decisions about resources and direction. It uses audit results as one of its inputs. A compliance audit is the mechanism that generates some of that information. The two serve different purposes and involve different people, though they are connected in the management system cycle.

Compliance Audit vs Inspection

An inspection checks whether a specific product, item, or condition meets a specification at a point in time. Inspecting a batch of incoming goods to check dimensions is an inspection. Auditing the process that manages incoming goods inspection is a compliance audit. Audits examine systems and processes. Inspections examine products and conditions. Both are important, but they are not the same thing.

What Auditors Actually Do in a Compliance Audit

If you have never been involved in a compliance audit from the auditor's side, it can be hard to picture what the work actually involves. Here is a realistic picture of what happens.

Planning and Preparation

Before the audit starts, the auditor defines the scope, objectives, and criteria. They review relevant documented information, including the management system documentation, previous audit reports, corrective action records, and any legal or regulatory requirements that apply. They develop an audit plan and, usually, a checklist or set of audit questions to guide the on site work.

Good planning is what separates a useful compliance audit from a superficial one. An auditor who arrives without understanding the applicable requirements, the organisation's context, or the risk areas will miss things that matter.

Gathering Evidence

During the audit, the auditor collects evidence through three main methods: reviewing documents and records, interviewing people, and observing operations. These three methods work together. A document might say that a procedure exists. An interview might reveal that workers are not following it. An observation might confirm which account is accurate.

The auditor is looking for objective evidence, not impressions. A finding that a procedure is not being followed needs to be supported by specific records, specific statements from specific people, or specific observations. Vague impressions do not constitute audit evidence.

Forming Findings and Conclusions

At the end of the audit, the auditor analyses the evidence and forms findings. A finding might be a nonconformity, where the evidence shows that a requirement is not being met. It might be an observation or opportunity for improvement, where the evidence suggests a risk or weakness that has not yet resulted in a nonconformity. Or it might be a positive finding, confirming that a requirement is being met effectively.

The auditor then forms an overall conclusion about the audit. For a certification audit, the conclusion might be a recommendation to grant, maintain, or withdraw certification. For an internal audit, the conclusion gives management a view of how well the system is functioning.

Reporting

The audit findings and conclusions are documented in an audit report. A good audit report is clear, specific, and actionable. It tells the reader exactly what was found, what requirement it relates to, and what the evidence was. It does not use vague language or make recommendations that are impossible to act on. Understanding what audit findings are and how they are classified is essential background for anyone writing or responding to audit reports.

Compliance Audits Under ISO Management System Standards

For most quality, safety, and environmental professionals in Australia, compliance audits happen in the context of ISO management system standards. Here is how compliance auditing appears across the most common standards.

ISO 9001 Quality Management Systems

ISO 9001 requires internal audits under Clause 9.2. These audits must check whether the quality management system conforms to the organisation's own requirements and to the requirements of the standard. They must also check whether the system is effectively implemented and maintained. The internal audit programme must be planned, taking into account the importance of the processes and the results of previous audits.

ISO 14001 Environmental Management Systems

ISO 14001 requires both internal audits under Clause 9.2 and a specific compliance evaluation process under Clause 9.1.2. The compliance evaluation is a distinct activity that checks whether the organisation is meeting its compliance obligations, including legal requirements, permit conditions, and other obligations it has accepted. This is a compliance audit in its purest form: a systematic check against defined legal and other requirements.

ISO 45001 Occupational Health and Safety Management Systems

ISO 45001 requires internal audits under Clause 9.2 and compliance evaluation under Clause 9.1.2, similar to ISO 14001. The compliance obligations in a safety context include WHS legislation, codes of practice, and any other requirements the organisation has accepted. Given the potential consequences of non compliance in a safety context, these audits carry significant weight.

ISO 27001 Information Security Management Systems

ISO 27001 requires internal audits under Clause 9.2. In an information security context, compliance audits check whether the organisation's information security controls are functioning as intended, whether policies are being followed, and whether the organisation is meeting any relevant legal obligations, such as the Australian Privacy Act or sector specific requirements.

Common Compliance Audit Findings and What They Signal

After conducting hundreds of external certification audits across Australia and internationally, certain patterns emerge in what compliance audits uncover. These are not sector specific problems. They appear across industries and management system types.

Legal registers that are not current. The register was built at the time of certification and has not been updated since. New legislation has come into force, permit conditions have changed, or the organisation's activities have changed in ways that create new compliance obligations. The register does not reflect reality.

Procedures that exist but are not followed. The documented system looks complete, but when you interview workers and observe operations, you find that the actual practice is different from what the procedure says. Sometimes this is because the procedure was written without involving the people who do the work. Sometimes it is because the procedure was updated but the change was not communicated. Either way, the compliance gap is real.

Compliance evaluations that are not evidence based. The organisation has a record saying it evaluated compliance, but there is no evidence of how that evaluation was conducted, what was checked, or what the results were. Ticking a box is not a compliance evaluation.

Corrective actions that address symptoms rather than causes. A nonconformity is raised, a quick fix is applied, and the finding is closed. But the underlying cause is not addressed, so the same problem appears again at the next audit. This is one of the most common patterns in compliance audit follow up work.

Preparing for a Compliance Audit as a Quality or Safety Manager

If you are responsible for managing a compliance audit, whether as the person being audited or as the person coordinating the internal audit programme, there are practical things you can do to make the process more effective.

First, make sure your audit criteria are clearly defined before the audit starts. Know exactly which requirements apply to your organisation and make sure the auditor has access to them. Ambiguity about what is being audited against leads to disputes about findings.

Second, make sure your people understand what a compliance audit is and what to expect. Workers who are anxious or defensive during an audit tend to give incomplete answers, which can lead to findings that could have been avoided. Understanding the difference between internal and certification audits helps teams know what to expect from each type.

Third, treat compliance audit findings as information, not as attacks. A finding that a requirement is not being met is valuable information. It tells you where your system has a gap. The appropriate response is to understand why the gap exists and address the root cause, not to argue about whether the finding is valid.

Finally, make sure your corrective action process is robust. The compliance audit is only as valuable as the action it generates. If findings are closed without genuine root cause analysis and effective corrective action, the audit has not added value. It has just produced paperwork.

Building Auditor Competence for Compliance Auditing

Conducting a compliance audit well requires specific competence. You need to understand the requirements you are auditing against, you need to be able to gather and evaluate evidence objectively, and you need to be able to communicate findings clearly and without bias.

For internal auditors, this competence is typically built through a structured internal auditor training course. For those who want to conduct compliance audits as a profession, including certification body auditors and independent compliance auditors, a lead auditor qualification is the standard pathway.

At Audit Workshop, our training programmes cover compliance auditing across ISO 9001, ISO 14001, ISO 45001, ISO 27001, ISO 42001, ISO 37001, and ISO 13485. Whether you are preparing for your first internal audit or building toward a career as a lead auditor, our courses are built around practical audit skills, not just theory. Choosing between an internal auditor and lead auditor course depends on where you are in your career and what you want to be able to do. Our team can help you work out the right starting point.

Frequently Asked Questions

A compliance audit is any structured examination that checks whether an organisation is meeting defined requirements, including laws, standards, contracts, or internal policies. An internal audit is a specific type of compliance audit conducted by or on behalf of the organisation itself, often referred to as a first party audit. All internal audits under ISO management system standards are forms of compliance audit, but not all compliance audits are internal audits. A compliance audit conducted by a regulator or a certification body is external to the organisation.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor Training Course
20+ enrolled
View Details
Exemplar Global certified
ISO 9001:2015 Lead Auditor Training Course badge
ISO 9001:2015 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
ISO 45001:2018 Lead Auditor Training Course
15+ enrolled
View Details
Exemplar Global certified
ISO 45001:2018 Lead Auditor Training Course badge
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
ISO 14001:2026 Lead Auditor Training Course
10+ enrolled
View Details
Exemplar Global certified
ISO 14001:2026 Lead Auditor Training Course badge
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.