Exemplar Global Certified Courses from USD 99. Ending Soon!

What Is an Audit? A Plain English Guide

AW

Team @ Audit Workshop

12 min read
What Is an Audit? A Plain English Guide

Start Here: What an Audit Actually Is

If you have just been told your organisation is getting audited, or you are considering a career in auditing, the word itself can feel loaded. It carries connotations of scrutiny, fault-finding, and stress. The reality is far more straightforward, and once you understand what an audit actually is, the whole process becomes much less intimidating.

An audit is a systematic, independent, and documented process for obtaining evidence and evaluating it objectively to determine the extent to which criteria are met. That is the formal definition from ISO 19011, the international guidelines for auditing management systems. In plain terms, an audit is a structured way of checking whether what is supposed to happen is actually happening, and whether the results are what they should be.

This guide covers the fundamentals: what an audit is, why organisations conduct them, the different types you will encounter, and what actually happens during one. Whether you are a quality manager preparing for your first certification audit, an HSE professional building an internal audit programme, or someone exploring auditing as a career, this article will give you a solid foundation.

The Core Purpose of an Audit

Before getting into types and processes, it helps to understand what an audit is trying to achieve. There are three things an audit is fundamentally designed to do.

Verify conformance

An audit checks whether an organisation is doing what it says it does, and whether what it does meets a defined set of requirements. Those requirements might come from an ISO standard like ISO 9001, from legislation, from a contract, or from the organisation's own documented procedures. The auditor gathers evidence and compares it against those requirements to determine whether the organisation conforms.

Drive improvement

A well-conducted audit does not just find problems. It identifies where a system is working well and where there are gaps, weaknesses, or risks. Those findings give management the information they need to make targeted improvements. This is why ISO standards require internal audits as part of the management system, not just as a compliance exercise, but as a genuine tool for improvement.

Provide assurance

Audits give stakeholders confidence that a management system is functioning as intended. That might be confidence for a customer that their supplier has a reliable quality system, confidence for a regulator that safety obligations are being met, or confidence for senior management that the organisation's environmental controls are effective.

What an Audit Is Not

It is worth being direct about what an audit is not, because misunderstandings here cause a lot of unnecessary anxiety.

An audit is not an inspection. An inspection is a point-in-time check of a product, service, or physical condition. An audit examines the system that produces those outputs, not the outputs themselves. An auditor checking your quality management system is not there to inspect every product on the line. They are there to verify the processes that control quality are in place and working.

An audit is not a witch hunt. A professional auditor is not looking for people to blame. They are examining systems and processes. When a nonconformity is found, the question is always about what the system failed to prevent, not who made a mistake.

An audit is not consulting. An auditor identifies findings and reports them. They do not design your corrective actions or tell you how to fix your system. That distinction matters, particularly for third-party auditors who must maintain independence.

Understanding the difference between an audit and an inspection is one of the first things new auditors need to get clear in their minds.

The Three Types of Audits

Audits are broadly categorised into three types based on who conducts them and for what purpose. ISO 19011 refers to these as first, second, and third party audits.

First party audits (internal audits)

A first party audit is conducted by or on behalf of the organisation itself. These are what most people call internal audits. The organisation audits its own management system against its own requirements, the requirements of the ISO standard it operates to, or both. The purpose is to identify nonconformities and opportunities for improvement before an external party finds them.

Internal audits are a mandatory requirement under ISO 9001, ISO 14001, and ISO 45001. They must be planned, conducted by competent auditors who are independent of the work being audited, and the results must feed into management review. A robust internal audit programme is one of the clearest indicators that a management system is genuinely functioning rather than just existing on paper.

Second party audits

A second party audit is conducted by one organisation on another, typically a customer auditing a supplier. The organisation doing the auditing has a direct interest in the outcome. A manufacturer might audit a key component supplier to verify that the supplier's quality controls are adequate. A government agency might audit a contracted service provider. These audits are driven by commercial or contractual relationships.

Second party audits tend to be more focused than third-party certification audits. They often concentrate on specific processes, products, or risk areas rather than the entire management system.

Third party audits

A third party audit is conducted by an independent external body with no vested interest in the outcome. Certification audits conducted by accredited certification bodies are the most common example. When an organisation seeks ISO 9001 certification, a third-party auditor from the certification body assesses the management system against the standard's requirements. If the system meets those requirements, the organisation is issued a certificate.

Third party audits also include regulatory audits, where a government authority audits an organisation for compliance with legislation, and audits conducted by accreditation bodies on certification bodies themselves.

The Audit Process: What Actually Happens

Regardless of the type of audit, the process follows a consistent structure. ISO 19011 outlines this in detail, but here is a practical summary of what happens at each stage.

Initiating the audit

Every audit starts with a clear purpose. The audit client (the person or organisation requesting the audit) defines the objectives, scope, and criteria. The objectives state what the audit is trying to achieve. The scope defines the boundaries, which processes, sites, or parts of the organisation are included. The criteria are the requirements the organisation will be measured against.

A competent audit team is then selected. For internal audits, this is usually one or more internal auditors who are independent of the area being audited. For certification audits, the certification body assigns qualified lead auditors.

Preparing for the audit

Good preparation is what separates a productive audit from a chaotic one. The auditor reviews documented information relevant to the scope, including the management system documentation, previous audit reports, nonconformity records, and any applicable legal or regulatory requirements. From this review, the auditor develops an audit plan and prepares checklists or audit questions.

The audit plan is shared with the auditee in advance. It sets out the schedule, who will be interviewed, which areas will be visited, and the timing of the opening and closing meetings.

Conducting the audit

The audit begins with an opening meeting. The auditor introduces the team, confirms the scope and objectives, explains the audit process, and gives the auditee an opportunity to ask questions. A well-run opening meeting sets a professional and collaborative tone for everything that follows.

The main audit activities involve three types of evidence gathering: interviewing people, reviewing documents and records, and observing activities and conditions. The auditor asks questions, follows up on responses, requests records as evidence, and observes processes in action. Good auditors use a mix of open questions to get people talking, probing questions to dig deeper, and observation to verify that what people say matches what actually happens on the floor.

As evidence is gathered, the auditor evaluates it against the audit criteria and records findings. Findings include conformities (things that meet requirements), nonconformities (things that do not), and observations or opportunities for improvement.

Reporting the findings

The audit concludes with a closing meeting, where the auditor presents the findings to the auditee. This is not a surprise. Professional auditors do not ambush auditees with findings they have not seen before. The closing meeting is an opportunity to confirm the findings, clarify any misunderstandings, and agree on the process for addressing nonconformities.

A formal audit report is then prepared and issued. The report documents the audit objectives, scope, criteria, evidence gathered, findings, and conclusions. For certification audits, the conclusion includes a recommendation regarding certification status.

Following up

For audits that identify nonconformities, the process does not end at the closing meeting. The auditee must investigate the root cause of each nonconformity, implement corrective actions, and provide evidence that those actions have been effective. The auditor or audit programme manager then verifies that the corrective actions have been completed satisfactorily. This follow-up step is where the real improvement happens.

Key Terms Every Auditor and Auditee Should Know

Audit terminology can be confusing at first. Here are the most important terms explained simply.

  • Audit criteria: The requirements used as a reference point. This might be an ISO standard, a procedure, a legal requirement, or a contractual obligation.
  • Audit evidence: Records, statements, or observations that are relevant to the audit criteria and can be verified. Evidence must be objective, meaning it is based on facts rather than opinions.
  • Audit finding: The result of evaluating audit evidence against audit criteria. A finding can be a conformity, a nonconformity, or an observation.
  • Nonconformity: A failure to meet a requirement. Nonconformities are classified as major (a significant failure that affects the system's ability to achieve its intended outcomes) or minor (an isolated or less significant failure).
  • Auditee: The organisation or part of the organisation being audited.
  • Audit client: The person or organisation that requests the audit. In an internal audit, this is usually top management. In a certification audit, it is the organisation seeking certification.
  • Lead auditor: The auditor responsible for managing the audit team and the overall audit process.
  • Audit programme: The set of audits planned over a defined period, usually a year. An audit programme includes multiple individual audits covering different areas or processes.

For a deeper look at how findings are classified, the article on audit findings, observations, and nonconformities covers the distinctions clearly.

What Makes a Good Audit

Not all audits are equally useful. An audit that ticks boxes but does not generate genuine insight is a wasted opportunity. Here is what distinguishes a well-conducted audit from a superficial one.

Independence and objectivity

The auditor must be independent of the work being audited. This does not mean they need to be from outside the organisation, but they cannot audit their own work or work in an area where they have a direct interest in the outcome. Independence protects the integrity of the findings.

Evidence-based conclusions

Every finding must be supported by objective evidence. An auditor cannot raise a nonconformity based on a gut feeling or a vague impression. If the evidence does not support the finding, the finding does not stand. This is one of the seven principles of auditing outlined in ISO 19011.

Competence of the auditor

An auditor needs two things: knowledge of the audit process and knowledge of the subject matter being audited. Someone who knows ISO 9001 inside out but has never set foot in a manufacturing environment will struggle to audit a production process effectively. Auditor competence is built through training, experience, and ongoing professional development.

A systematic approach

Audits should follow a defined methodology. Random conversations and unstructured walkthroughs do not constitute an audit. The auditor needs a plan, prepared questions, a method for sampling records, and a consistent approach to evaluating evidence.

Why Audits Matter for Your Organisation

For quality managers, HSE professionals, and environmental managers, audits are one of the most powerful tools available for maintaining and improving a management system. They create a feedback loop. The audit identifies gaps, corrective actions close those gaps, and the next audit verifies the improvements have stuck.

Organisations that treat audits as a compliance burden tend to get compliance-focused audits that find little of value. Organisations that treat audits as a genuine improvement tool tend to build audit programmes that actually drive performance.

The difference is usually in how leadership engages with audit findings. If the management review receives audit results and acts on them, the programme has real teeth. If findings sit in a register without follow-up, the audit programme becomes a paper exercise. Understanding the difference between internal and certification audits helps organisations use each type of audit for its intended purpose.

Getting Started as an Auditor

If you are interested in auditing as a career or want to build your auditing skills, the path is well-defined. Most people start with an internal auditor course, which gives them the skills to plan and conduct internal audits within their own organisation. From there, many progress to a lead auditor course, which prepares them to manage audit teams and conduct third-party certification audits.

The choice between these levels depends on what you want to do. If your goal is to run internal audits for your employer, an internal auditor course is the right starting point. If you want to work as a certification auditor or lead audit teams across organisations, a lead auditor course is what you need. The article on ISO lead auditor vs internal auditor courses walks through this decision in detail.

At Audit Workshop, courses are available at Foundation, Internal Auditor, and Lead Auditor levels across ISO 9001, ISO 14001, and ISO 45001. All courses are delivered by Dilawar Laghari, a certified lead auditor with over 14 years of compliance experience and more than 500 external certification audits conducted across Australia, the Middle East, and South Asia. If you want to build practical auditing skills grounded in real audit practice, not just theory, explore the available courses at auditworkshop.com.

Frequently Asked Questions

An inspection is a point-in-time check of a product, service, or physical condition to determine whether it meets a specification. An audit examines the system or process that produces those outputs, not the outputs themselves. An auditor looks at whether the management system is functioning as intended and whether requirements are being met systematically, rather than checking individual items one by one.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.