Start Here: What an Audit Actually Is
If you have just been told your organisation is getting audited, or you are considering a career in auditing, the word itself can feel loaded. It carries connotations of scrutiny, fault-finding, and stress. The reality is far more straightforward, and once you understand what an audit actually is, the whole process becomes much less intimidating.
On this page
An audit is a systematic, independent, and documented process for obtaining evidence and evaluating it objectively to determine the extent to which criteria are met. That is the formal definition from ISO 19011, the international guidelines for auditing management systems. In plain terms, an audit is a structured way of checking whether what is supposed to happen is actually happening, and whether the results are what they should be.
This guide covers the fundamentals: what an audit is, why organisations conduct them, the different types you will encounter, and what actually happens during one. Whether you are a quality manager preparing for your first certification audit, an HSE professional building an internal audit programme, or someone exploring auditing as a career, this article will give you a solid foundation.
The Core Purpose of an Audit
Before getting into types and processes, it helps to understand what an audit is trying to achieve. There are three things an audit is fundamentally designed to do.
Verify conformance
An audit checks whether an organisation is doing what it says it does, and whether what it does meets a defined set of requirements. Those requirements might come from an ISO standard like ISO 9001, from legislation, from a contract, or from the organisation's own documented procedures. The auditor gathers evidence and compares it against those requirements to determine whether the organisation conforms.
Drive improvement
A well-conducted audit does not just find problems. It identifies where a system is working well and where there are gaps, weaknesses, or risks. Those findings give management the information they need to make targeted improvements. This is why ISO standards require internal audits as part of the management system, not just as a compliance exercise, but as a genuine tool for improvement.
Provide assurance
Audits give stakeholders confidence that a management system is functioning as intended. That might be confidence for a customer that their supplier has a reliable quality system, confidence for a regulator that safety obligations are being met, or confidence for senior management that the organisation's environmental controls are effective.
Exemplar Global Recognised Training ProviderRTP No. 310970What an Audit Is Not
It is worth being direct about what an audit is not, because misunderstandings here cause a lot of unnecessary anxiety.
An audit is not an inspection. An inspection is a point-in-time check of a product, service, or physical condition. An audit examines the system that produces those outputs, not the outputs themselves. An auditor checking your quality management system is not there to inspect every product on the line. They are there to verify the processes that control quality are in place and working.
An audit is not a witch hunt. A professional auditor is not looking for people to blame. They are examining systems and processes. When a nonconformity is found, the question is always about what the system failed to prevent, not who made a mistake.
An audit is not consulting. An auditor identifies findings and reports them. They do not design your corrective actions or tell you how to fix your system. That distinction matters, particularly for third-party auditors who must maintain independence.
Understanding the difference between an audit and an inspection is one of the first things new auditors need to get clear in their minds.
The Three Types of Audits
Audits are broadly categorised into three types based on who conducts them and for what purpose. ISO 19011 refers to these as first, second, and third party audits.
First party audits (internal audits)
A first party audit is conducted by or on behalf of the organisation itself. These are what most people call internal audits. The organisation audits its own management system against its own requirements, the requirements of the ISO standard it operates to, or both. The purpose is to identify nonconformities and opportunities for improvement before an external party finds them.
Internal audits are a mandatory requirement under ISO 9001, ISO 14001, and ISO 45001. They must be planned, conducted by competent auditors who are independent of the work being audited, and the results must feed into management review. A robust internal audit programme is one of the clearest indicators that a management system is genuinely functioning rather than just existing on paper.
Second party audits
A second party audit is conducted by one organisation on another, typically a customer auditing a supplier. The organisation doing the auditing has a direct interest in the outcome. A manufacturer might audit a key component supplier to verify that the supplier's quality controls are adequate. A government agency might audit a contracted service provider. These audits are driven by commercial or contractual relationships.
Second party audits tend to be more focused than third-party certification audits. They often concentrate on specific processes, products, or risk areas rather than the entire management system.
Third party audits
A third party audit is conducted by an independent external body with no vested interest in the outcome. Certification audits conducted by accredited certification bodies are the most common example. When an organisation seeks ISO 9001 certification, a third-party auditor from the certification body assesses the management system against the standard's requirements. If the system meets those requirements, the organisation is issued a certificate.
Third party audits also include regulatory audits, where a government authority audits an organisation for compliance with legislation, and audits conducted by accreditation bodies on certification bodies themselves.
The Audit Process: What Actually Happens
Regardless of the type of audit, the process follows a consistent structure. ISO 19011 outlines this in detail, but here is a practical summary of what happens at each stage.
Initiating the audit
Every audit starts with a clear purpose. The audit client (the person or organisation requesting the audit) defines the objectives, scope, and criteria. The objectives state what the audit is trying to achieve. The scope defines the boundaries, which processes, sites, or parts of the organisation are included. The criteria are the requirements the organisation will be measured against.
A competent audit team is then selected. For internal audits, this is usually one or more internal auditors who are independent of the area being audited. For certification audits, the certification body assigns qualified lead auditors.
Preparing for the audit
Good preparation is what separates a productive audit from a chaotic one. The auditor reviews documented information relevant to the scope, including the management system documentation, previous audit reports, nonconformity records, and any applicable legal or regulatory requirements. From this review, the auditor develops an audit plan and prepares checklists or audit questions.
The audit plan is shared with the auditee in advance. It sets out the schedule, who will be interviewed, which areas will be visited, and the timing of the opening and closing meetings.
Conducting the audit
The audit begins with an opening meeting. The auditor introduces the team, confirms the scope and objectives, explains the audit process, and gives the auditee an opportunity to ask questions. A well-run opening meeting sets a professional and collaborative tone for everything that follows.
The main audit activities involve three types of evidence gathering: interviewing people, reviewing documents and records, and observing activities and conditions. The auditor asks questions, follows up on responses, requests records as evidence, and observes processes in action. Good auditors use a mix of open questions to get people talking, probing questions to dig deeper, and observation to verify that what people say matches what actually happens on the floor.
As evidence is gathered, the auditor evaluates it against the audit criteria and records findings. Findings include conformities (things that meet requirements), nonconformities (things that do not), and observations or opportunities for improvement.
Reporting the findings
The audit concludes with a closing meeting, where the auditor presents the findings to the auditee. This is not a surprise. Professional auditors do not ambush auditees with findings they have not seen before. The closing meeting is an opportunity to confirm the findings, clarify any misunderstandings, and agree on the process for addressing nonconformities.
A formal audit report is then prepared and issued. The report documents the audit objectives, scope, criteria, evidence gathered, findings, and conclusions. For certification audits, the conclusion includes a recommendation regarding certification status.
Following up
For audits that identify nonconformities, the process does not end at the closing meeting. The auditee must investigate the root cause of each nonconformity, implement corrective actions, and provide evidence that those actions have been effective. The auditor or audit programme manager then verifies that the corrective actions have been completed satisfactorily. This follow-up step is where the real improvement happens.
Key Terms Every Auditor and Auditee Should Know
Audit terminology can be confusing at first. Here are the most important terms explained simply.
- Audit criteria: The requirements used as a reference point. This might be an ISO standard, a procedure, a legal requirement, or a contractual obligation.
- Audit evidence: Records, statements, or observations that are relevant to the audit criteria and can be verified. Evidence must be objective, meaning it is based on facts rather than opinions.
- Audit finding: The result of evaluating audit evidence against audit criteria. A finding can be a conformity, a nonconformity, or an observation.
- Nonconformity: A failure to meet a requirement. Nonconformities are classified as major (a significant failure that affects the system's ability to achieve its intended outcomes) or minor (an isolated or less significant failure).
- Auditee: The organisation or part of the organisation being audited.
- Audit client: The person or organisation that requests the audit. In an internal audit, this is usually top management. In a certification audit, it is the organisation seeking certification.
- Lead auditor: The auditor responsible for managing the audit team and the overall audit process.
- Audit programme: The set of audits planned over a defined period, usually a year. An audit programme includes multiple individual audits covering different areas or processes.
For a deeper look at how findings are classified, the article on audit findings, observations, and nonconformities covers the distinctions clearly.
What Makes a Good Audit
Not all audits are equally useful. An audit that ticks boxes but does not generate genuine insight is a wasted opportunity. Here is what distinguishes a well-conducted audit from a superficial one.
Independence and objectivity
The auditor must be independent of the work being audited. This does not mean they need to be from outside the organisation, but they cannot audit their own work or work in an area where they have a direct interest in the outcome. Independence protects the integrity of the findings.
Evidence-based conclusions
Every finding must be supported by objective evidence. An auditor cannot raise a nonconformity based on a gut feeling or a vague impression. If the evidence does not support the finding, the finding does not stand. This is one of the seven principles of auditing outlined in ISO 19011.
Competence of the auditor
An auditor needs two things: knowledge of the audit process and knowledge of the subject matter being audited. Someone who knows ISO 9001 inside out but has never set foot in a manufacturing environment will struggle to audit a production process effectively. Auditor competence is built through training, experience, and ongoing professional development.
A systematic approach
Audits should follow a defined methodology. Random conversations and unstructured walkthroughs do not constitute an audit. The auditor needs a plan, prepared questions, a method for sampling records, and a consistent approach to evaluating evidence.
Exemplar Global Recognised Training ProviderRTP No. 310970Why Audits Matter for Your Organisation
For quality managers, HSE professionals, and environmental managers, audits are one of the most powerful tools available for maintaining and improving a management system. They create a feedback loop. The audit identifies gaps, corrective actions close those gaps, and the next audit verifies the improvements have stuck.
Organisations that treat audits as a compliance burden tend to get compliance-focused audits that find little of value. Organisations that treat audits as a genuine improvement tool tend to build audit programmes that actually drive performance.
The difference is usually in how leadership engages with audit findings. If the management review receives audit results and acts on them, the programme has real teeth. If findings sit in a register without follow-up, the audit programme becomes a paper exercise. Understanding the difference between internal and certification audits helps organisations use each type of audit for its intended purpose.
Getting Started as an Auditor
If you are interested in auditing as a career or want to build your auditing skills, the path is well-defined. Most people start with an internal auditor course, which gives them the skills to plan and conduct internal audits within their own organisation. From there, many progress to a lead auditor course, which prepares them to manage audit teams and conduct third-party certification audits.
The choice between these levels depends on what you want to do. If your goal is to run internal audits for your employer, an internal auditor course is the right starting point. If you want to work as a certification auditor or lead audit teams across organisations, a lead auditor course is what you need. The article on ISO lead auditor vs internal auditor courses walks through this decision in detail.
At Audit Workshop, courses are available at Foundation, Internal Auditor, and Lead Auditor levels across ISO 9001, ISO 14001, and ISO 45001. All courses are delivered by Dilawar Laghari, a certified lead auditor with over 14 years of compliance experience and more than 500 external certification audits conducted across Australia, the Middle East, and South Asia. If you want to build practical auditing skills grounded in real audit practice, not just theory, explore the available courses at auditworkshop.com.













