Exemplar Global Certified Courses from USD 99. Ending Soon!

What Is a Joint Audit: How They Work and When to Use One

AW

Team @ Audit Workshop

14 min read
What Is a Joint Audit: How They Work and When to Use One

A joint audit is an audit conducted by two or more auditing organisations together, against the same auditee, at the same time. Rather than each organisation sending its own team on separate occasions, they combine their resources into a single audit event. The term appears in ISO 19011 as a recognised audit type, and in practice it shows up most often in supply chain contexts, regulatory settings, and situations where multiple stakeholders have an overlapping interest in a single organisation's management system.

If you are a quality manager, HSE manager, or auditor working in complex supply chains or regulated industries, understanding what a joint audit is, how it differs from a combined audit, and what challenges it brings will save you considerable confusion when you encounter one in the field.

How a Joint Audit Differs from a Combined Audit

These two terms get mixed up constantly, so it is worth being precise before going any further.

A combined audit involves auditing two or more management systems at the same organisation during a single audit event, with one audit team. For example, auditing ISO 9001 and ISO 14001 together. The team is unified, the client is typically one certification body, and the audit plan covers multiple standards simultaneously.

A joint audit is different in a specific and important way. The distinguishing factor is that two or more auditing organisations are involved. Both teams are present. Both have their own objectives, potentially their own criteria, and their own reporting obligations. The auditee is the same, the timing is the same, but the audit is being conducted by multiple independent parties working in coordination.

You might encounter a joint audit in situations such as:

  • Two certification bodies auditing a supplier against different customer requirements simultaneously
  • A government regulator and a certification body conducting a joint assessment of a regulated facility
  • Two major customers who both rely on the same critical supplier agreeing to conduct a single joint supplier audit rather than putting that supplier through two separate visits
  • A prime contractor and a client organisation jointly auditing a subcontractor

The practical effect for the auditee is that they face a larger, more complex audit team with potentially different agendas, but they only have to open their doors once.

What ISO 19011 Says About Joint Audits

ISO 19011 is the international guideline for auditing management systems. It acknowledges joint audits and provides some high level guidance on how they should be managed. The standard notes that when a joint audit is conducted, the auditing organisations involved need to agree beforehand on responsibilities, reporting, and how the audit team will be structured and led.

Specifically, the guidance points to the need for:

  • Clear agreement on who leads the audit team overall
  • Defined roles for each auditing organisation's personnel
  • Agreement on how findings will be reported and to whom
  • Clarity around confidentiality, particularly where one auditing organisation's findings may be sensitive to the other

ISO 19011 does not prescribe a single method for running joint audits because the circumstances vary so widely. What it does is signal that joint audits require more upfront coordination than standard audits. That coordination is where most problems arise in practice.

For a broader grounding in how ISO 19011 shapes modern audit practice, the article How the ISO 19011 Guidelines Shape Modern Audit Practice provides useful context on the principles that underpin all audit types, including joint audits.

Who Leads a Joint Audit?

This is the first practical question that needs answering before any joint audit begins, and it is often the most politically sensitive one.

Each auditing organisation will typically have its own lead auditor. In a joint audit, one of these individuals needs to take overall responsibility for managing the audit process. This person is sometimes called the lead auditor for the joint audit, or the coordinating lead auditor. The other lead auditor operates within the team but is not directing the overall programme.

Who takes this role is usually determined by:

  • Which organisation initiated the audit
  • Which organisation has the primary relationship with the auditee
  • The relative scope of each organisation's audit objectives
  • Contractual or regulatory requirements

In supplier audit contexts, the customer with the larger commercial relationship or the more critical dependency often takes the lead. In certification body joint audits, the body that holds the primary certification contract typically coordinates. In regulatory joint audits, the regulator almost always leads.

Whatever the arrangement, it needs to be agreed in writing before the audit begins. Ambiguity about leadership during a joint audit creates confusion on the floor, conflicting signals to the auditee, and disputes about findings afterwards.

Planning a Joint Audit: The Coordination Challenge

Joint audits require significantly more planning than single organisation audits. The coordination effort is real and should not be underestimated.

Agreeing Audit Objectives and Criteria

Each auditing organisation brings its own objectives. These may overlap, complement each other, or in some cases create tension. Before the audit, the organisations need to map out where their objectives align and where they diverge.

If two certification bodies are auditing the same supplier against different customer-specific requirements, the criteria will differ. The audit plan needs to reflect this clearly, so the auditee knows what is being assessed by whom.

Building the Joint Audit Plan

A single, unified audit plan is strongly preferable to two parallel plans. The unified plan shows the auditee who will be where and when, which team members are responsible for which areas, and how the day will be structured. Without a unified plan, you end up with scheduling conflicts, duplicated interviews, and confused auditees who do not know which team to escort where.

The audit plan should specify:

  • The overall audit scope and objectives for the joint audit
  • Each auditing organisation's specific objectives and criteria
  • The coordinating lead auditor
  • Team member assignments by area or process
  • Interview schedule and who will conduct each interview
  • Arrangements for daily briefings between the two teams
  • Closing meeting format and who will present findings

Confidentiality Agreements

This is a practical issue that often gets overlooked. If two auditing organisations are working together, they will inevitably share information during the audit. One organisation may be a certification body, the other a customer. The customer may learn things about the supplier's system that the supplier would prefer to keep from commercial competitors.

Confidentiality expectations need to be agreed before the audit starts. Both auditing organisations should be clear about what information can be shared between them, what goes into shared reports, and what remains within each organisation's own reporting channel.

Conducting a Joint Audit on the Day

Once the planning is done, the actual conduct of a joint audit follows the same general process as any management system audit. But there are some practical differences that experienced auditors will recognise.

Opening Meeting

The opening meeting for a joint audit typically involves both audit teams and the auditee's senior management. The coordinating lead auditor runs the meeting. Both lead auditors should be introduced clearly. The auditee needs to understand who represents each organisation, what each organisation is there to assess, and how findings will be reported.

A common mistake is having two lead auditors both trying to run the opening meeting. This signals poor coordination to the auditee immediately. Agree beforehand who speaks and in what order.

Evidence Gathering

Audit teams from each organisation may work in parallel across different areas of the facility, or they may work together through each process. The approach depends on the size of the facility, the scope of each organisation's audit, and the available audit days.

Where teams work in parallel, daily debriefs between the two lead auditors are essential. Findings from one team may be relevant to the other's scope. For example, a document control issue found by one team may affect a process being audited by the other.

Where teams work together through each process, the risk is that the auditee faces an overwhelming number of auditors in each interview. More than two or three auditors in a room can intimidate auditees and reduce the quality of evidence gathered. Managing the team's physical presence is part of the coordinating lead auditor's job.

Closing Meeting

The closing meeting needs careful management. Both organisations will have findings. The question is how they are presented. Options include:

  • A unified closing meeting where all findings from both organisations are presented together
  • Separate closing presentations, one per organisation, in sequence
  • A combined presentation of shared findings, followed by organisation-specific findings

The unified approach is generally cleaner for the auditee. It avoids repetition and reduces the length of the meeting. But it requires both organisations to agree on how their findings are categorised and presented, which can be difficult if one organisation has raised a major nonconformity that the other has not.

Reporting After a Joint Audit

Reporting is one of the most practically complex aspects of joint audits. Each auditing organisation typically has its own reporting obligations, its own report format, and its own audience.

There are several common approaches:

  • Separate reports: Each organisation produces its own audit report covering its own findings. This is the simplest approach from each organisation's internal perspective, but it can create confusion for the auditee who receives two reports that may overlap or even appear to contradict each other.
  • Joint report: Both organisations contribute to a single report. This is cleaner for the auditee but requires agreement on format, language, and ownership of findings. It also raises questions about liability if findings are later disputed.
  • Summary report plus appendices: A shared summary covers the overall audit outcome, with each organisation's detailed findings in separate appendices. This is a reasonable middle ground in many situations.

Whatever approach is used, the auditee should know before the audit starts what reporting they will receive and from whom. Surprises in the reporting phase erode trust in the audit process.

When Joint Audits Make Sense and When They Do Not

Joint audits are not always the right tool. They make sense in specific circumstances and can create more problems than they solve in others.

When Joint Audits Work Well

  • When two organisations have genuinely overlapping interests in the same auditee and audit burden reduction is a real benefit
  • When the auditee is a critical supplier to multiple parties and separate audits would be disruptive to operations
  • When regulatory and commercial audit objectives can be meaningfully combined without compromising either
  • When both auditing organisations have compatible audit cultures and can agree on coordination arrangements without significant conflict

When Joint Audits Create Problems

  • When the two auditing organisations have conflicting objectives or standards that cannot be reconciled in a single audit plan
  • When confidentiality requirements make information sharing between the two organisations inappropriate
  • When one organisation has significantly more audit scope than the other, leading to an imbalanced team
  • When the auditee has not genuinely agreed to the joint arrangement and feels coerced into it

From the auditee's perspective, a joint audit can feel like being audited by committee. The quality of the experience depends heavily on how well the two organisations have coordinated before they arrive on site.

Joint Audits in the Supply Chain Context

The most common setting for joint audits in Australian industry is supply chain management. Large organisations in mining, construction, defence, and energy often share critical suppliers. Rather than each conducting their own supplier audits, they sometimes agree to conduct a joint audit together.

This approach has real benefits. The supplier faces one audit instead of two or three. The auditing organisations share the cost and resource burden. The findings are seen by all parties simultaneously, which can accelerate corrective action.

But it requires trust between the auditing organisations. If two competing customers are conducting a joint audit of a shared supplier, they need to be comfortable sharing what they find. In practice, this limits joint audits to situations where the auditing organisations have a cooperative rather than competitive relationship.

For anyone building a supplier audit programme, understanding the difference between joint audits, second party audits, and third party certification audits is essential. The article What Is a Second Party Audit and When Should You Use One? covers the second party audit context in detail, which is where most joint supplier audits sit.

Joint Audits and Auditor Competence

Participating in a joint audit as an auditor requires specific competencies beyond those needed for standard audits. You need to be able to:

  • Work effectively within a team that includes auditors from another organisation, with potentially different methods and expectations
  • Manage your own scope without stepping on the other team's territory
  • Communicate clearly with a coordinating lead auditor who may not be from your own organisation
  • Handle situations where you and the other team reach different conclusions about the same evidence

For auditors building towards lead auditor status, exposure to joint audits is genuinely valuable experience. It tests your ability to coordinate, communicate, and maintain professional judgement under conditions that are more complex than a standard solo audit.

If you are thinking about the broader pathway from internal auditor to lead auditor, the article ISO Auditor Career Path: From Internal Auditor to Lead Auditor outlines the competence development journey in practical terms.

What Auditees Should Know Before a Joint Audit

If your organisation is about to be subject to a joint audit, there are several things worth understanding before the team arrives.

First, you have the right to understand who each auditing organisation is, what their specific objectives are, and what will happen with the findings. Do not assume the two organisations have sorted out all the coordination details. Ask directly.

Second, prepare your team for a larger audit presence than usual. More auditors means more simultaneous interviews, more areas being accessed at once, and more demands on your time as the host. Brief your department managers accordingly.

Third, clarify the reporting arrangements in advance. Ask each auditing organisation how they will report their findings, what format the reports will take, and what timelines apply for corrective action responses.

Fourth, if you have concerns about confidentiality, raise them before the audit starts. If there is sensitive commercial information that you are comfortable sharing with one auditing organisation but not the other, that needs to be addressed in the planning phase, not on the day.

How Audit Training Prepares You for Joint Audits

Joint audits are not covered in depth in most introductory auditor training, but the competencies developed through good lead auditor training are directly applicable. Understanding how to plan audits, manage audit teams, handle complex auditee situations, and produce clear findings are all skills that transfer directly to joint audit contexts.

At Audit Workshop, the lead auditor courses for ISO 9001, ISO 14001, and ISO 45001 are built around real audit practice, not textbook theory. The training covers audit planning, team management, evidence gathering, and reporting in ways that prepare auditors for the complexity of real world audits, including situations like joint audits where coordination and professional judgement are tested. If you are working towards lead auditor credentials or want to sharpen your practical audit skills, explore the ISO Lead Auditor vs Internal Auditor course comparison to find the right starting point for your current level.

Frequently Asked Questions

A joint audit involves two or more separate auditing organisations conducting an audit together against the same auditee at the same time. A combined audit involves one audit team auditing two or more management systems simultaneously at the same organisation. The key distinction is whether multiple auditing organisations are involved, not whether multiple standards are being assessed.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.