First-, Second-, and Third-Party Audits

Three audit pathways using common methods but supporting different decisions

A supplier can face three audits of the same management system in a single quarter. Its own internal team reviews the control of measuring equipment and finds incomplete records. A strategic customer examines the same process and makes continued approval conditional on corrective action. Weeks later, a certification body records a nonconformity and sends the file forward for the relevant certification decision.

The evidence may look almost identical. The consequences do not.

First-, second-, and third-party audits are distinguished less by interviews, sampling, or finding formats than by the relationship between the evaluator, the organization being evaluated, and the users of the result. That relationship shapes the purpose of the engagement, the degree of independence expected, and the decision that can follow.

The category describes a relationship, not a technique

ISO 19011:2026 provides guidance for auditing management systems and can support first-, second-, and third-party audits. Its principles and processes establish a common core: define objectives, scope, and criteria; obtain verifiable evidence; evaluate that evidence; develop findings; and reach conclusions.

A shared method, however, does not make the three engagements interchangeable.

In conformity assessment language, a first-party activity is performed by the provider or organization on itself; a second-party activity is performed by someone with a user or purchaser interest; and a third-party activity is performed by an independent body that is neither the provider nor a user interested in the object being assessed. The classification describes that position, not the auditor’s seniority or professionalism.

It is not determined simply by who pays, either. An organization usually contracts and pays its certification body, yet the audit remains third party because the body is expected to operate impartially and does not act as the buyer, supplier, or representative of either party’s commercial interests.

Dimension First party Second party Third party
Typical example Internal management system audit Customer audit of a supplier Certification audit
Primary interest Understand and improve the organization’s own system Gain confidence for a commercial or contractual relationship Provide an independent assessment of conformity
Relationship with the auditee Part of the organization or acting on its behalf Has an interest as customer, purchaser, or another related party Neither the provider nor a user interested in the assessed object
Expected independence Impartiality and sufficient separation within the organization Separation from the supplier, although the purchaser’s interest remains Institutional impartiality and freedom from first- or second-party interests
Immediate output Findings, conclusions, and internal actions A report supporting supplier approval, monitoring, or development An audit report feeding the formal certification process
Decision that follows Management priorities, corrections, and improvement Contract, continue, qualify, escalate, or exit the relationship Grant, maintain, renew, suspend, reduce, or withdraw certification, as applicable

This is not a hierarchy. A third-party audit is not automatically “better” than an internal audit, and a supplier audit is not an incomplete certification audit. Each exists to support a different decision.

First party: the organization audits itself to manage better

A first-party audit is normally an internal audit performed by the organization or on its behalf. It may be conducted by employees or by an external service provider acting as the internal audit resource. What matters is that the work is commissioned for the organization’s own needs and concerns its own management system.

Its value should extend well beyond preparing for the next certification visit. A well-designed internal audit can assess whether the system operates as intended, controls are applied, requirements are fulfilled, and risks or opportunities require management attention. Its conclusions may inform management review, corrective action, resource allocation, and continual improvement.

Independence in this setting is functional and practical, not complete separation from the organization. Auditors should act objectively, avoid reviewing their own work when that would compromise judgment, and remain free from pressure that distorts the scope or conclusions. Perfect separation may be unrealistic in a small organization, so proportionate safeguards may include cross-auditing, rotation, external support, or independent review.

The output primarily belongs to the organization. It may identify conformity, nonconformities, risks, good practices, or improvement opportunities, but it does not by itself create a certificate recognized by external parties.

Second party: the customer’s interest shapes the scope

Second-party audits are most visible in supply chains. A customer audits a supplier, or appoints someone to do so on its behalf, to decide whether it can rely on that supplier to meet technical, contractual, legal, quality, sustainability, security, or continuity requirements.

The auditor may be independent from the supplier and perform rigorous professional work, but the engagement is not neutral toward the commercial decision. It legitimately represents the customer’s user interest. That is not a weakness; it is the defining feature of a second-party audit.

The scope can be more targeted than a certification audit. A manufacturer may concentrate on traceability, engineering changes, production capacity, cybersecurity, or sub-tier suppliers because those areas directly affect its exposure. It may also apply proprietary criteria that exceed a general standard or examine contractual obligations that a certification body is not expected to cover.

The conclusion usually informs procurement or third-party risk management: approve the supplier, assign a risk category, require improvement, increase monitoring, restrict awarded volume, or reconsider the relationship. The report has value for the organization that commissioned it, but it does not automatically create a conformity statement intended for the entire market.

A third-party certificate can reduce duplication, yet it does not necessarily remove the need for customer audits. The purchaser may require evidence over product-specific risks, proprietary requirements, or contractual conditions outside the certified scope.

Third party: the audit feeds a certification decision

Management system certification is a third-party conformity assessment activity. ISO/IEC 17021-1:2015 establishes principles and requirements for the competence, consistency, and impartiality of bodies that audit and certify management systems.

This creates a critical distinction: the audit and the certification are not exactly the same act.

The audit team collects and evaluates evidence, develops findings, and prepares a report. Certification results from the certification body’s subsequent review and decision process. A statement made during the closing meeting does not, by itself, grant a certificate. The body must consider the audit file, the treatment of nonconformities, and the applicable scheme rules before making its decision.

Independence is also more formally structured. The certification body must manage threats to impartiality arising from relationships, services, financial interests, commercial pressure, and other influences. The audited organization may be its fee-paying client, but the outcome cannot be driven by the desire to retain that contract.

Certification must also be distinguished from accreditation. An organization receives certification of its management system. The certification body may itself be accredited by an accreditation body operating against ISO/IEC 17011:2017. Accreditation adds confidence in the certification body’s competence, consistent operation, and impartiality within a defined scope; it does not make the certified company an “accredited company.”

The same nonconformity can support different decisions

Assume all three audits identify that several evaluations of critical suppliers were not completed within the required period.

The internal audit may ask: what failed in the process, what risk does it create, and what should management correct? The second-party customer may ask: can this supplier continue meeting our conditions, and what additional monitoring do we need? In the certification audit, the team evaluates the situation against the applicable criteria and documents the nonconformity for the certification process.

No conclusion should be stretched beyond its mandate:

  • Passing an internal audit does not guarantee success in a customer or certification audit.
  • Passing a supplier audit does not generate a management system certificate.
  • Holding a certificate does not mean every product is certified, that nonconformities cannot exist, or that every customer must abandon its own assessments.
  • A third-party audit does not transfer responsibility for managing the system to the certification body; management remains accountable.

Before commissioning an audit, ask three questions: Who needs confidence, what decision must they make, and what degree of independence does that decision require? When management needs to understand and improve its own system, first party is appropriate. When a purchaser needs to manage supplier risk, second party is the natural model. When the market needs an independent statement of conformity, a third-party process under the relevant scheme is required.

The distinction is not about prestige or the number of pages in the report. It is about the chain of accountability that connects evidence to a decision. When that chain is clear, each audit produces the kind of confidence it was designed to provide.

Sources