1.2 First-, Second- & Third-Party Context

Key Takeaways

  • First-party audits are internal: the organization (or someone acting on its behalf) audits itself for conformity and improvement
  • Second-party audits are external audits by a customer or other interested party with a contractual/business relationship (commonly supplier audits)
  • Third-party audits are performed by independent bodies—typically certification/registration or accreditation bodies—without the customer–supplier contract relationship of a second-party audit
  • Internal versus external is about organizational boundary; first/second/third-party is about the relationship among auditor, auditee, and client
  • Independence and objectivity requirements tighten as you move toward second- and especially third-party work; internal auditors must still avoid auditing their own work
Last updated: August 2026

Relationship is a classification axis of its own

BoK I.A.2 classifies audits by the relationship among the parties, independent of product/process/system type (I.A.1) and independent of purpose (I.A.3). A supplier process audit can be second-party; an internal process audit of the same workflow can be first-party; a registrar’s process-focused surveillance visit can be third-party. Same process object—three different relationships.

Use this three-question filter on every scenario:

  1. Who requested the audit (the client)?
  2. Who is being audited (the auditee)?
  3. Who performs the audit, and what is their organizational independence from the auditee?

First-party audits (internal)

A first-party audit is conducted by, or on behalf of, the organization itself on its own products, processes, or systems. Internal audit programs, corporate audit groups, and contracted auditors hired by the company to audit its own sites all fall here when the company is both client and (in a sense) auditee organization.

Typical purposes: verify QMS conformity, prepare for external audits, identify improvement opportunities, feed management review, and satisfy standards that require internal audits (e.g., ISO 9001).

Independence implications:

  • Internal auditors should not audit their own work or areas where they have direct operational responsibility that compromises objectivity.
  • Reporting lines ideally go to a level that protects the audit function from undue influence (often top management or a board/audit committee in larger organizations).
  • Using external consultants as internal auditors does not convert the engagement to third-party certification—it remains first-party if the organization is auditing itself for internal assurance.

Scenario

A medical-device manufacturer’s corporate quality auditor schedules an annual internal audit of the complaint-handling process at Plant B. Findings go to plant management and to the management review package. First-party, process-focused, internal context.


Second-party audits (customer / contractual interested party)

A second-party audit is performed by a party that has a business or contractual interest in the auditee—most often a customer auditing a supplier, or an organization auditing a contractor, license holder, or other partner against purchase agreements, quality agreements, or supplier requirements.

Typical purposes: supplier qualification (pre-award), ongoing supplier surveillance, for-cause supplier investigation after escapes, confirmation that contract quality clauses and quality agreements are implemented.

Characteristics that show up on exam stems:

  • Purchase orders, supplier manuals, quality agreements, or SLA criteria define requirements
  • Results influence sourcing, scorecards, approved-supplier lists, or business continuation
  • The auditor represents the customer’s interests, not a certification scheme

Independence implications:

  • Second-party auditors are independent of the supplier’s management but not independent of the commercial relationship—findings can be commercially sensitive.
  • Ethics still apply: objective evidence, confidentiality, no gifts that impair judgment, clear scope against contractual criteria.
  • Second-party audits do not issue ISO management-system certificates (that is third-party certification body work), though customers may accept them in lieu of some oversight activities.

Scenario

An automotive OEM sends its supplier quality engineer to audit a tier-2 molder against the OEM’s supplier quality requirements and the purchase contract after a dimensional escape. Second-party (customer → supplier), typically process- and product-oriented, external to the auditee.


Third-party audits (independent / certification)

A third-party audit is conducted by an independent organization that is neither the auditee nor a customer auditing for its own contract management—classically a certification/registration body or an accreditation body assessing a conformity-assessment body. Independence and impartiality rules (for example under ISO/IEC 17021-1 for management-system certification) are formal and auditable.

Typical purposes: initial certification, surveillance, recertification, accreditation assessments, sometimes regulatory inspections when the inspector is an independent authority (context-dependent wording on exams—focus on independence and absence of customer–supplier audit relationship).

Outputs: certificates, continued certification decisions, major/minor nonconformities against a public or scheme standard—not supplier scorecard points (though businesses care about certificate status).

Independence implications:

  • Highest formal impartiality expectations among the three parties
  • Certification auditors must avoid conflicts (recent consulting on the same QMS, financial interest, etc.)
  • The auditee pays fees, but the auditor’s duty is to the scheme/standard and impartial decision process, not to "help the customer pass at all costs"

Scenario

A registrar’s audit team conducts a Stage 2 certification audit against ISO 9001 and recommends certification to the certification body’s decision function. Third-party system audit.


Internal vs external context

ContextMeaningCommon party mapping
InternalAuditor and auditee are in the same organization (or audit is on behalf of that organization for self-assessment)Usually first-party
ExternalAuditor comes from outside the auditee organizationSecond-party or third-party

Nuances for CQA:

  • A corporate auditor from HQ visiting a wholly owned plant is still first-party / internal relative to the legal entity group, even if plant staff experience it as "outsiders."
  • A customer is external → second-party.
  • A registrar is external → third-party.
  • Outsourced internal audit (consultant paid by the company to run the internal audit program) remains first-party for classification, with contractual requirements for competence and independence from the work audited.

Do not equate "external" exclusively with "third-party." Second-party audits are external too.


Independence implications for CQA scenarios

Exam items often test whether you can spot impaired independence or mislabeled party type:

SituationPreferred analysis
Production supervisor audits the production line they run daily as the only "internal audit"Independence impaired; first-party program design is weak
Customer uses a third-party firm as its agent to audit a supplier against the customer’s checklistStill second-party in purpose/relationship (customer interest); the firm is not acting as a certification body
Certification body employee recently consulted on implementing the same QMS being certifiedConflict for third-party certification work
Internal auditor from Design audits Manufacturing (no dual responsibility)Acceptable first-party independence pattern if organizationally free of the audited work
Supplier "audits itself" and emails results to the customer as the only oversightSupplier’s work is first-party; customer may treat it as input, not as a completed second-party audit

Practical rule: Party type follows who’s interest and authority the audit serves, not the employment badge alone. A body acting under a certification scheme → third-party. A body acting under a purchase contract for the buyer → second-party. A body acting for the organization’s own management system → first-party.


How party type interacts with other BoK topics

  • Criteria (I.C): First-party often uses internal procedures + chosen standards; second-party leans on contracts and quality agreements; third-party leans on scheme standards and certification rules.
  • Reporting: Second-party reports may be confidential between customer and supplier; third-party outcomes affect public certificate status; first-party reports feed internal CAPA and management review.
  • CAPA leverage: Customers can impose commercial consequences; registrars can suspend/withdraw certification; internal programs rely on management authority.
/practice/cqaPractice questions with detailed explanations

Key Takeaways

  • First-party = organization audits itself (internal assurance and improvement).
  • Second-party = customer or contractual party audits the other party (often supplier oversight).
  • Third-party = independent body for certification/accreditation (formal impartiality).
  • External ≠ automatically third-party; second-party is also external.
  • Independence means freedom from the work and pressures that bias findings—stricter formal controls apply in third-party schemes.
Test Your Knowledge

A hospital’s quality department audits its own sterile processing department against hospital procedures and AAMI-aligned work instructions, reporting results to the quality council. This is best classified as a:

A
B
C
D
Test Your Knowledge

Which scenario is the clearest example of a second-party audit?

A
B
C
D
Test Your Knowledge

For independence, which assignment is most problematic in a first-party audit program?

A
B
C
D
Test Your Knowledge

A customer hires an independent consulting firm to audit a key supplier using the customer’s supplier quality checklist and to report only to the customer’s supplier quality manager. Party classification is primarily:

A
B
C
D