Exemplar Global Certified Courses from USD 99. Ending Soon!

What Is a System Audit? A Plain English Guide for Auditors and Quality Managers

AW

Team @ Audit Workshop

13 min read
What Is a System Audit? A Plain English Guide for Auditors and Quality Managers

Understanding the System Audit

A system audit is one of the most common types of audits conducted under ISO management system standards. If you have ever sat through an ISO 9001 certification audit, participated in an internal audit programme, or prepared your organisation for a third party assessment, you have almost certainly been involved in a system audit, even if nobody called it that at the time.

At its core, a system audit evaluates whether a management system as a whole is established, implemented, maintained, and continually improved in line with a defined set of requirements. Those requirements might come from an ISO standard, a regulatory framework, or an organisation's own documented policies and procedures. The audit is not focused on a single product, a single transaction, or a single process in isolation. It looks at the entire management system and how its components work together.

This article explains what a system audit is, how it differs from other audit types, what auditors actually do during one, and why understanding the distinction matters for anyone working in quality, safety, environmental, or information security management.

System Audit vs Process Audit vs Product Audit

These three terms often cause confusion, and it is worth separating them clearly before going further.

What a system audit covers

A system audit looks at the management system as a whole. It examines whether the organisation has established a system that meets the requirements of the relevant standard, whether that system is actually being followed in practice, and whether it is producing the outcomes it was designed to produce. A system audit under ISO 9001, for example, would look at how the quality management system is structured, how leadership is engaged, how risks and opportunities are addressed, how processes are planned and controlled, and how the organisation monitors and improves performance across all of those elements.

What a process audit covers

A process audit zooms in on a specific process. It asks whether that process is being carried out as planned and whether it is effective. A process audit of the purchasing function, for instance, would look at how suppliers are selected, evaluated, and monitored, and whether the controls in place are working. Process audits are often conducted as part of a broader system audit, but they can also stand alone.

What a product audit covers

A product audit is even more specific. It examines a finished product or service output against defined specifications. Product audits are common in manufacturing and construction, where you need to confirm that what has been produced actually meets the requirements before it leaves the facility or site.

The key distinction is scope. A system audit is broad. It is concerned with the architecture and performance of the entire management system. Process and product audits are narrower and more targeted.

When Is a System Audit Used?

System audits appear in several different contexts, and understanding those contexts helps you prepare for them effectively.

Internal system audits

ISO standards require organisations to conduct internal audits of their management systems. ISO 9001 Clause 9.2, ISO 14001 Clause 9.2, ISO 45001 Clause 9.2, and their equivalents in other standards all establish this requirement. The organisation must plan, establish, implement, and maintain an audit programme that covers the full scope of the management system over a defined period, typically a year.

Internal system audits are conducted by people within the organisation, or by external parties acting on the organisation's behalf. The auditors must be independent of the activities they are auditing. The purpose is to give the organisation an honest view of how well its management system is functioning before the external certification body arrives.

Certification audits

When an organisation seeks ISO certification for the first time, the certification body conducts a system audit in two stages. Stage 1 is typically a documentation review and readiness assessment. Stage 2 is the full system audit, where auditors verify that the management system is implemented and effective across all areas within the scope of certification. Both stages together constitute the initial system audit for certification purposes.

Surveillance audits

After certification is granted, the certification body conducts surveillance audits, usually annually, to confirm that the management system continues to meet requirements. These are also system audits, though they typically do not cover every element of the standard in a single visit. They focus on high risk areas and any issues raised during previous audits.

Recertification audits

At the end of the three year certification cycle, the organisation undergoes a recertification audit. This is a full system audit that reassesses the entire management system against the standard requirements. It is essentially the same in scope as the original Stage 2 audit.

What Auditors Actually Look at During a System Audit

If you are preparing for a system audit, whether as the quality manager hosting it or as the auditor conducting it, it helps to understand what the audit is actually trying to establish. There are four fundamental questions that underpin every system audit.

Is the system established?

The auditor will look for evidence that the management system has been designed and documented in a way that meets the requirements of the standard. This includes the scope of the system, the policies and objectives, the processes and their interactions, the roles and responsibilities, and the documented information required by the standard. If the system exists only on paper and has not been tailored to the organisation's actual context, that will become apparent quickly.

Is the system implemented?

This is where many organisations fall short. A well documented system that nobody follows is not a functioning management system. Auditors will interview staff at all levels, observe work being done, and sample records to confirm that the system is actually being used. They will ask workers how they know what to do, how they report problems, and what happens when something goes wrong. The answers to those questions tell the auditor a great deal about whether the system is real or just a set of documents sitting on a shared drive.

Is the system maintained?

A management system needs to be kept current. Processes change, people change, risks change, and the system needs to keep pace. Auditors will look at how the organisation manages changes to its system, how it keeps its documented information up to date, and how it ensures that training and competence records reflect the current state of the workforce. A system that was well implemented two years ago but has not been reviewed since is not being maintained.

Is the system being continually improved?

ISO standards are explicit about the requirement for continual improvement. Auditors will look at how the organisation uses data from monitoring and measurement, internal audits, customer feedback, nonconformities, and management reviews to drive improvement. If the management review minutes show the same issues being discussed year after year without any meaningful action, that is a signal that improvement is not happening in any genuine sense.

How a System Audit Is Structured

System audits follow a defined process, regardless of whether they are internal or external. Understanding this structure helps both auditors and auditees know what to expect.

Planning and preparation

Before the audit begins, the auditor or audit team prepares an audit plan that defines the scope, objectives, criteria, schedule, and methods to be used. For a system audit, the criteria are the requirements of the relevant ISO standard, supplemented by the organisation's own documented policies and procedures. The auditor will review relevant documentation in advance, including the previous audit report, any outstanding nonconformities, and the organisation's context and risk information.

Opening meeting

The audit begins with an opening meeting where the auditor explains the purpose and scope of the audit, confirms the schedule, and answers any questions from the auditee. This is also where the auditor establishes the ground rules, including how findings will be communicated and what happens at the end of the audit.

Evidence gathering

The bulk of the audit is spent gathering evidence. Auditors use three main methods: document and record review, interviews with personnel, and direct observation of activities. For a system audit, all three methods are essential. You cannot audit a management system by looking at documents alone. You need to talk to people and see what is actually happening on the ground.

The auditor will typically follow the structure of the standard, working through each clause and gathering evidence of conformity or nonconformity. In practice, a skilled auditor will not work through the clauses in strict numerical order. They will follow the evidence, moving between clauses as the audit trail leads them. This is sometimes called process based auditing, and it tends to produce more meaningful findings than a rigid clause by clause approach.

Audit team meetings

On larger audits with multiple team members, the audit team will meet periodically during the audit to share findings, identify gaps, and agree on how to allocate remaining audit time. These internal discussions are important for ensuring that the audit team presents a coherent and consistent set of findings at the end.

Closing meeting

The audit concludes with a closing meeting where the auditor presents the findings to the auditee. This includes any nonconformities, observations, and opportunities for improvement identified during the audit. The auditor will also state the overall audit conclusion, which for a certification audit will include a recommendation regarding certification status.

Common Findings in System Audits

After conducting hundreds of system audits across a wide range of industries and ISO standards, certain patterns emerge. The following types of findings come up repeatedly.

Context of the organisation is superficial

Many organisations have completed a context analysis because the standard requires it, but the analysis is generic and has not been used to shape the management system in any meaningful way. The internal and external issues identified are vague, the interested parties list is incomplete, and there is no visible connection between the context analysis and the risks and objectives that flow from it.

Objectives are not measurable

ISO standards require measurable quality, environmental, or safety objectives. In practice, many organisations set objectives that cannot be measured or that have no defined targets. An objective like

improve customer satisfaction
without a baseline, a target, and a defined measurement method is not going to satisfy an auditor.

Internal audits are not risk based

The standard requires the internal audit programme to take into account the importance of the processes concerned and the results of previous audits. In many organisations, the audit schedule is simply a list of departments or clauses rotated through the year with no consideration of risk or performance. High risk processes get the same audit frequency as low risk ones, and areas with recurring problems are not audited more often.

Management review is a tick box exercise

The management review is supposed to be a genuine leadership conversation about the performance of the management system. In practice, it is often a brief meeting where the quality manager presents a slide deck and the attendees nod along. There is no meaningful discussion, the inputs are not all addressed, and the outputs are vague action items that are never followed up.

Corrective actions lack root cause analysis

When nonconformities are raised, the corrective action process should include a genuine analysis of root cause before a solution is implemented. Many organisations jump straight to the correction, fix the immediate problem, and close the nonconformity without addressing why it happened in the first place. The same nonconformity then reappears in the next audit cycle.

System Audit vs Compliance Audit

A system audit is sometimes confused with a compliance audit, but they are not the same thing. A compliance audit focuses specifically on whether the organisation is meeting its legal and regulatory obligations. A system audit under an ISO standard will include compliance as one element, since standards like ISO 14001 and ISO 45001 explicitly require organisations to evaluate their compliance with legal requirements. However, the system audit goes much further, examining the entire management system architecture and its effectiveness.

In practice, a system audit conducted under ISO 45001, for example, will look at legal compliance as part of Clause 9.1.2, but it will also look at leadership commitment, hazard identification, operational controls, worker participation, incident investigation, and a dozen other elements that a pure compliance audit would not touch.

Why the System Audit Matters

It is worth being direct about this. A system audit is only valuable if it is conducted with genuine independence and rigour. An internal audit programme that exists only to satisfy the requirements of the standard, conducted by auditors who are reluctant to raise findings because it creates work, produces nothing of value. The organisation ends up with a set of audit reports that say everything is fine, followed by a certification audit that finds significant gaps.

The system audit is the mechanism through which an organisation gets an honest view of its management system. It identifies what is working, what is not, and where improvement effort should be directed. Done well, it is one of the most useful tools available to a quality manager, safety manager, or environmental manager. Done poorly, it is a waste of everyone's time.

If you want to understand more about how different audit types compare and where system audits sit within the broader audit landscape, the article on process audit vs system audit goes into more detail on the practical differences between the two approaches.

Building the Skills to Conduct Effective System Audits

Conducting a system audit well requires a specific set of skills. You need to understand the requirements of the standard, know how to plan and structure an audit, be able to gather and evaluate evidence, and be capable of writing clear and defensible findings. These are not skills that come automatically from working in quality or safety management. They need to be developed through structured training and practice.

For those starting out, an internal auditor course provides the foundation. It covers the audit process from planning through to reporting, with practical exercises that simulate real audit conditions. For those looking to conduct audits for certification bodies or lead audit teams, a lead auditor course builds on that foundation and adds the skills needed to manage the audit process at a higher level.

At Audit Workshop, our courses are built around practical audit skills, not just theory. Whether you are preparing to run your first internal system audit or looking to develop your skills as a lead auditor across multiple ISO standards, our training is designed to give you the tools you need to conduct audits that actually add value. You can explore our internal auditor pathway or learn more about which course level suits your situation before making a decision.

Frequently Asked Questions

A system audit evaluates the entire management system, examining how all elements work together to meet the requirements of a standard such as ISO 9001 or ISO 45001. A process audit focuses on a specific process, assessing whether it is being carried out as planned and whether it is effective. System audits are broader in scope, while process audits provide deeper examination of individual activities. In practice, a system audit will often include process audits as part of its evidence gathering approach.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
Limited timeUSD 199(Was USD 789)
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
Limited timeUSD 199(Was USD 789)
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
Limited timeUSD 199(Was USD 789)
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.