The word “audit” gets used so loosely inside organizations that its meaning has nearly collapsed. Understanding the three distinct audit types isn’t bureaucratic pedantry — it’s the foundation of a functioning quality system.
If you’ve recently stepped into a quality management role — or you’re building an audit program from scratch — you’ve probably noticed that the word “audit” appears constantly, attached to very different things. Someone mentions an internal audit on Tuesday and a supplier audit on Thursday, and then the certification body calls to schedule its annual visit. Three audits. Three completely different purposes, relationships, and stakes.
Getting this distinction straight early matters. The way you prepare for each, who conducts them, what they’re measuring, and what you do with the findings — all of it differs significantly. Conflating them leads to wasted resources at best, and failed certifications or broken supplier relationships at worst.
The three-party model: how audits are classified
The international standard ISO 19011 — which governs audit management systems — organizes audits into what it calls first-party, second-party, and third-party arrangements. These terms describe the relationship between the auditor and the organization being audited. Everything else flows from there.
Internal audits: the engine of your QMS
Internal audits are where quality management actually happens on a day-to-day basis. Despite being the least glamorous of the three types, they carry the most operational weight — and poorly run internal audit programs are one of the most common reasons organizations struggle when a certification body eventually shows up.
There are two main forms worth distinguishing: process audits and system audits.
A process audit examines a specific operational workflow — incoming inspection, order fulfillment, nonconformance handling — to determine whether it’s being performed as defined and whether it’s delivering expected outcomes. It’s narrow by design. You’re not evaluating the whole quality system; you’re going deep on one procedure.
A system audit takes the wider view, assessing whether the overall QMS — or a significant portion of it — conforms to the applicable standard, typically ISO 9001, and is actually implemented in practice. These are structurally closer to what a certification body would conduct, which is precisely why organizations use them to stress-test readiness before external scrutiny arrives.
ISO 9001:2015, clause 9.2, requires that internal audits be planned taking into account the importance of the processes concerned and the results of previous audits. That last part gets overlooked more often than it should. Your audit schedule should be risk-informed, not simply a calendar exercise where every department gets the same hour once a year regardless of what’s happened since.
Second-party audits: the supplier relationship in formal clothing
When your organization sources components, materials, or services from external suppliers — especially where quality failures carry significant downstream consequences — you need some basis for confidence that those suppliers are managing their processes appropriately. A second-party audit is how you establish that confidence in a structured, documented way.
From the supplier’s perspective, being audited by a customer can feel adversarial. The better-run supplier audit programs treat it as a collaborative assessment instead. You’re not trying to catch them out. You’re trying to understand whether their quality controls are robust enough that you can rely on what they deliver.
The scope of a supplier audit varies considerably depending on the industry and risk level. Some organizations limit it to a facility walkthrough and review of key quality records. Others conduct highly structured assessments against sector-specific requirements — IATF 16949 in automotive, AS9100 in aerospace, FSSC 22000 in food safety. The formality of the process should match the criticality of what you’re purchasing.
One practical consideration: second-party audits require meaningful investment of time and, often, travel. Many organizations manage this by using questionnaire-based desktop reviews for lower-risk suppliers, reserving on-site visits for critical, new, or previously problematic ones.
Third-party audits: where credentials are earned
The certification audit is what most people picture when they hear the word “audit” in a quality context. An accredited certification body sends an independent auditor to assess whether your QMS meets the requirements of ISO 9001 or another applicable standard. If it does, you receive a certificate. If it doesn’t, you get nonconformances that must be addressed before certification is granted or maintained.
Third-party audits typically follow a two-stage process for initial certification. Stage 1 — sometimes called a documentation review or readiness audit — assesses whether your QMS is sufficiently developed to proceed. Stage 2 examines actual implementation on the ground. Surveillance audits then occur annually or semi-annually, with a full recertification cycle every three years.
The key distinction from internal audits isn’t just independence — it’s consequence. A nonconformance in an internal audit is an improvement opportunity you handle internally. A major nonconformance in a certification audit can suspend or withdraw your certificate, with real effects on customer contracts and regulatory standing.
A mistake new quality managers make more often than they should
The most common misstep early in an audit journey is treating internal audits as a compliance checkbox — scheduling them because ISO 9001 requires it, running them superficially, and filing the records without acting on what was found. ISO 9001 management software can help quality teams move beyond simply recording audit findings by keeping follow-up actions visible and connected to the audit process.
The result is an internal audit program that generates paper but no improvement, and an organization that gets surprised when a certification body or a major customer finds the same gaps months later.
The second most common mistake is under-resourcing supplier audits relative to the actual risk those suppliers represent. Organizations spend months preparing for their certification audit while maintaining minimal oversight of the suppliers whose inputs most directly affect their product quality. Both mistakes tend to surface at exactly the wrong moment.
Where to start if you’re building a program
For most organizations beginning a formal QMS, the sequence that works is this: establish your internal audit schedule first, grounded in process risk and the scope of your quality system. Develop your supplier qualification criteria in parallel — identify which suppliers are critical and what level of oversight they require. Then, once your internal processes are reasonably stable and documented, engage a certification body for initial certification.
Each type of audit, run well, informs the others. Internal audits reveal the process weaknesses most likely to attract scrutiny from a certification body. Supplier audits surface risks that affect the inputs to your own processes. And the discipline of preparing for third-party scrutiny forces a clarity in documentation and implementation that benefits the entire system.
None of this happens automatically. It requires structure, trained auditors, a planned schedule, and software that keeps audit records, findings, and corrective actions connected and visible across the organization.
Managing your audit program shouldn’t require a spreadsheet and three email threads. QISS QMS brings internal audits, supplier assessments, corrective actions, and compliance records into a single connected platform — so your quality team spends less time chasing paper and more time acting on what the audits actually tell you. Book a demo to learn more.