Exemplar Global Certified Courses from USD 99. Ending Soon!

What Is an External Audit? A Plain English Guide for Quality and HSE Managers

AW

Team @ Audit Workshop

13 min read
What Is an External Audit? A Plain English Guide for Quality and HSE Managers

If your organisation holds ISO certification or is working towards it, you will encounter an external audit at some point. For many quality managers and HSE professionals, the term is used loosely to mean any audit conducted by someone from outside the business. That is broadly correct, but the detail matters. Understanding exactly what an external audit is, who conducts it, what they are looking for, and how it differs from an internal audit will help you prepare properly and get genuine value from the process.

This guide covers the full picture: the definition, the types, the stages, what auditors actually do on the day, and how to come out the other side with your certification intact and your system stronger.

Defining an External Audit

An external audit is an audit conducted by a party that is independent of the organisation being audited. The auditor has no employment relationship with the auditee organisation and no financial or operational stake in the outcome. That independence is the defining feature.

ISO 19011, the international guidelines for auditing management systems, classifies audits by party type. Internal audits are first party audits. External audits fall into two categories: second party and third party.

  • Second party audits are conducted by or on behalf of a party with an interest in the organisation, typically a customer or a contracting organisation auditing a supplier.
  • Third party audits are conducted by an independent certification body, regulatory authority, or other independent organisation with no direct commercial relationship with the auditee.

Both are external audits. The key difference is who is doing the auditing and why. A customer auditing your quality system before awarding a contract is a second party audit. A certification body assessing your ISO 9001 compliance is a third party audit. Both involve an auditor from outside your organisation examining your management system against defined criteria.

Types of External Audits

Certification Audits

The most common type of third party external audit for organisations seeking ISO certification. Certification audits are conducted in two stages. Stage 1 is a readiness review, typically conducted remotely or at your site, where the auditor reviews your documented system and confirms you are ready for the full assessment. Stage 2 is the on-site audit where the auditor evaluates whether your management system is implemented effectively and conforming to the requirements of the standard.

A successful Stage 2 results in a recommendation for certification. The certification body then issues a certificate, typically valid for three years, subject to ongoing surveillance.

Surveillance Audits

Once certified, your organisation is subject to surveillance audits, usually annually. These are not a full re-assessment. Instead, the auditor samples key elements of your system to confirm it is being maintained and continues to conform to the standard. Surveillance audits are shorter than certification audits but should not be treated as a formality. Nonconformities raised at surveillance can still result in suspension of certification if not addressed.

Recertification Audits

At the end of the three-year certification cycle, a recertification audit is required to renew the certificate. This is more comprehensive than a surveillance audit and covers the full scope of the management system. Think of it as a fresh certification audit conducted by an auditor who already has context about your organisation.

Second Party Supplier Audits

These are external audits conducted by customers, principal contractors, or organisations in a supply chain. If you supply goods or services to a large organisation, particularly in sectors like construction, mining, defence, or government, you may be subject to supplier audits on a regular basis. The criteria for these audits may be the customer's own requirements, a relevant ISO standard, or a combination of both.

Second party audits are often more focused than certification audits. The customer is interested in specific processes that affect their supply. They may not audit your entire management system, just the parts that matter to them.

Regulatory and Statutory Audits

Some industries are subject to audits conducted by government regulators or statutory bodies. These are also external audits, though they operate under different rules than ISO certification audits. Examples include WHS regulator inspections, environmental compliance audits, and NDIS quality audits. While the framework differs from ISO auditing, the principles of evidence-based assessment and impartial evaluation apply.

What an External Auditor Is Actually Looking For

This is where many organisations get caught out. They focus on documents and records and assume that having the right paperwork means they will pass. External auditors are not primarily looking for documents. They are looking for evidence that your management system is implemented, effective, and genuinely embedded in how the organisation operates.

Documents are evidence. But so are observations, interviews with staff, physical conditions on site, records of past performance, and the way people talk about their work. A lead auditor conducting a certification audit will triangulate across all of these. A perfect quality manual with a workforce that has never heard of it will not survive scrutiny.

Conformity to the Standard

The auditor will assess whether your management system meets the requirements of the relevant ISO standard. Every shall statement in the standard is a requirement. If your system does not address it, that is a potential nonconformity. The auditor will use your documented system as a starting point, then test whether what you have documented reflects what actually happens.

Implementation and Effectiveness

Conformity is not enough. The auditor wants to see that the system is working. Are quality objectives being monitored? Are corrective actions being closed out? Are internal audits being conducted at planned intervals? Are people aware of their responsibilities? These questions go beyond documentation into actual system performance.

Continual Improvement

ISO standards require organisations to continually improve their management systems. External auditors will look for evidence that the organisation is not just maintaining the status quo but actively identifying opportunities to improve and acting on them. Management review outputs, corrective action trends, and objective performance data all contribute to this picture.

The External Audit Process: Stage by Stage

Before the Audit

The certification body or auditing organisation will contact you to arrange the audit. You will receive an audit plan that sets out the scope, criteria, schedule, and the processes or areas to be covered. Review this carefully. If anything is unclear or if the scope does not match your certificate scope, raise it before the audit begins.

Prepare your team. Make sure the people who will be interviewed understand the purpose of the audit and know where to find relevant records. Brief process owners on what the auditor is likely to ask about their area. You do not need to rehearse scripted answers. You need people who understand their processes and can speak to them honestly.

Gather key documents the auditor will want to see: your management system manual or equivalent, your internal audit programme and recent reports, management review records, corrective action logs, and any records specific to the processes being audited. Having these ready saves time and reduces the chance of delays on the day.

The Opening Meeting

Every external audit begins with an opening meeting. The lead auditor will introduce the audit team, confirm the scope and criteria, explain the audit process, and invite questions. This meeting sets the tone. A well-run opening meeting puts the auditee team at ease and establishes a professional, collaborative atmosphere.

As the quality or HSE manager, you will typically chair the auditee side of this meeting. Introduce your team, confirm who will be accompanying auditors through different areas, and confirm any site-specific requirements such as inductions or PPE. Keep it professional and straightforward.

The On-Site Audit

The bulk of the audit involves the auditor moving through your organisation, interviewing staff, reviewing documents and records, and observing work activities. The auditor will follow an audit trail, starting with a process or requirement and tracing it through your system to verify that what should happen actually does happen.

Stay available but do not hover. Auditors need to speak with your people directly. Excessive management presence during interviews can inhibit honest responses. Your job during this phase is to facilitate access, answer questions about the system, and help the auditor find the evidence they need.

If the auditor identifies a potential issue, they may ask for additional evidence. Provide what you have. If a record genuinely does not exist, say so. Do not attempt to create records during the audit or produce documents that have been backdated. This will make things significantly worse.

The Closing Meeting

At the end of the audit, the lead auditor will present the findings in a closing meeting. This includes any nonconformities raised, observations or opportunities for improvement, and the overall audit conclusion. Listen carefully. You have the right to ask for clarification on any finding. You do not have to agree with every finding on the spot, but you should understand what evidence the auditor relied on.

For certification audits, the auditor will advise whether they are recommending certification, recommending certification subject to close-out of minor nonconformities, or not recommending certification due to major nonconformities. The final decision rests with the certification body, not the individual auditor.

Nonconformities in an External Audit: What Happens Next

Finding nonconformities in an external audit is not a disaster. It is a normal part of the process. What matters is how you respond.

Minor nonconformities require a corrective action response, typically within a defined timeframe set by the certification body. You need to identify the root cause, implement a correction and corrective action, and provide evidence of closure. The auditor or a colleague will review your response before the nonconformity is closed.

Major nonconformities are more serious. They indicate a significant failure of the management system or a complete absence of a required element. A major nonconformity must be resolved before certification can be granted or maintained. This may require a follow-up visit or a desktop review of evidence, depending on the certification body's procedures.

If you receive a major nonconformity, do not panic. Work through the root cause methodically. A genuine, well-evidenced corrective action will satisfy the auditor. A superficial response that does not address the underlying cause will not.

How External Audits Differ From Internal Audits

The most important difference is independence. An internal auditor is employed by the organisation and audits on behalf of management. An external auditor has no such relationship. This independence means external auditors can and do raise findings that internal audits might miss or avoid.

External audits also carry formal consequences. A failed internal audit is an internal matter. A failed external audit can result in suspension or withdrawal of certification, which has real commercial implications. This is why organisations that run rigorous internal audit programmes tend to perform better in external audits. The internal programme identifies and resolves issues before the external auditor finds them.

The scope is also different. Internal audits can be targeted at specific processes, clauses, or risk areas. External certification audits cover the full scope of the certified management system. Surveillance audits sample across the system, but over the three-year cycle, the certification body will typically cover all major elements.

For a detailed comparison of how these two types of audits relate to each other, the article on internal vs external audits covers the key distinctions in practical terms.

Preparing Your Organisation for an External Audit

The best preparation for an external audit is a well-functioning management system. If your system is genuinely implemented and your people understand it, you have little to fear from an external auditor. If your system exists only on paper, no amount of last-minute preparation will save you.

That said, there are practical steps that make the audit run more smoothly.

  • Confirm that all internal audits required under your programme have been conducted and that findings have been closed out.
  • Ensure the most recent management review has been completed and that outputs are documented.
  • Check that your corrective action register is current and that no open actions are overdue without a documented reason.
  • Brief process owners and frontline staff on the purpose of the audit and what to expect during interviews.
  • Prepare a clear site induction for the audit team and assign a competent guide for each auditor.
  • Confirm that all documented information is current, approved, and accessible to the people who use it.

If you are preparing for your first certification audit, the article on what to expect during an ISO certification audit provides a detailed walkthrough of the process from the auditee perspective.

The Value of External Audits Beyond Certification

It is easy to view external audits as a compliance exercise. You get audited, you maintain your certificate, and you move on. But experienced quality and HSE managers know that external audits, when approached with the right mindset, deliver genuine value.

An experienced external auditor brings perspective from dozens or hundreds of other organisations. They see patterns that internal teams miss. They ask questions that challenge assumptions. They identify gaps that have become invisible through familiarity. Even a finding that stings in the moment often points to something that genuinely needed attention.

Use the closing meeting as a learning opportunity, not just a report-out. Ask the auditor what they observed that was working well. Ask about observations and opportunities for improvement, not just nonconformities. Take notes. The auditor's perspective is a resource you are paying for, so use it.

Building the Skills to Manage External Audits Confidently

Quality managers and HSE professionals who understand how external audits work are far better positioned to prepare their organisations, respond to findings, and extract value from the process. That understanding comes from knowing what auditors are trained to look for and how they gather and evaluate evidence.

One of the most effective ways to build that understanding is to train as an auditor yourself. When you have sat on the auditor's side of the table, even in a training environment, you see your own management system differently. You start noticing gaps that were invisible before. You understand why auditors ask the questions they do.

At Audit Workshop, our internal auditor and lead auditor courses are built around practical audit skills, not just standard knowledge. Whether you are a quality manager preparing your team for an upcoming certification audit, or an HSE professional looking to add auditing credentials to your profile, our courses for ISO 9001, ISO 14001, and ISO 45001 give you the tools to approach external audits with confidence. You can explore the available courses at auditworkshop.com.

If you are unsure which training level suits your situation, the article on ISO Lead Auditor vs Internal Auditor: Which Course Do You Need? walks through the decision in plain terms.

Frequently Asked Questions

An internal audit is conducted by or on behalf of the organisation itself, using auditors who are employed by or contracted to the organisation. An external audit is conducted by an independent party, either a customer or contracting organisation conducting a supplier audit, or an independent certification body assessing the organisation against an ISO standard. The key distinction is independence. External auditors have no employment or operational relationship with the auditee, which means their findings carry a different level of objectivity and, in the case of certification audits, formal consequences for the organisation's certification status.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.