2.3 Quality Auditing Principles & Types

Key Takeaways

  • Audits are classified by party relationship: 1st party (internal self-assessment), 2nd party (customer auditing supplier), and 3rd party (independent certification registrar).
  • Audits are categorized by technical focus: System audits evaluate total QMS compliance, Process audits assess specific operational transformations, and Product audits evaluate end-item conformance to specifications.
  • ISO 19011:2018 establishes seven core auditing principles: Integrity, Fair Presentation, Due Professional Care, Confidentiality, Independence, Evidence-Based Approach, and Risk-Based Approach.
  • Auditor independence is paramount; auditors must remain objective, free from bias or conflict of interest, and must never audit their own direct work.
Last updated: July 2026

2.3 Quality Auditing Principles & Types

A Quality Audit is defined by ISO 19011 as a systematic, independent, and documented process for obtaining audit evidence and evaluating it objectively to determine the extent to which audit criteria are fulfilled. Auditing serves as a vital diagnostic tool within a Quality Management System (QMS), allowing leadership to verify compliance, evaluate process effectiveness, identify systemic vulnerabilities, and drive continual improvement.


1. Audit Categorization by Organizational Relationship (Parties)

Quality audits are classified into three primary categories based on the relationship between the auditing body, the audited entity (auditee), and the client initiating the audit.

1st Party Audit (Internal Audit)

  • Auditor: Trained internal employees of the organization (or external consultants contracted by the organization).
  • Auditee: Internal departments, functions, or production lines of the same organization.
  • Purpose: To evaluate the ongoing effectiveness of the internal QMS, verify adherence to internal SOPs, ensure readiness for external assessments, and identify improvement opportunities.
  • Key Constraint: Auditors must not audit their own work (independence rule).

2nd Party Audit (Customer / External Supplier Audit)

  • Auditor: Customer quality auditors, procurement specialists, or external consultants representing the buyer.
  • Auditee: Existing or prospective suppliers, sub-tier vendors, or contract manufacturers.
  • Purpose: To assess supplier capability prior to contract award, evaluate supplier QMS compliance, investigate recurring nonconformities in incoming shipments, or verify PPAP / AS9100 supply chain mandates.
  • Characteristics: Governed by contractual obligations and purchase order terms rather than universal certification requirements.

3rd Party Audit (Certification / Registrar Audit)

  • Auditor: Independent, accredited Certification Bodies (CBs) or Registrars (e.g., BSI, TÜV, DNV, ANAB accredited).
  • Auditee: Organization seeking or maintaining formal QMS certification (ISO 9001, AS9100, IATF 16949, ISO 13485).
  • Purpose: To provide unbiased, expert verification that the organization's QMS fully conforms to specified standard requirements.
  • Outcome: Leads to formal issuance, maintenance, suspension, or withdrawal of QMS registration certificates.

2. Audit Categorization by Technical Scope & Focus

Audits are further categorized by their technical breadth and operational depth: System, Process, and Product audits.

Audit TypeFocus / ScopePrimary ObjectiveExample Audit ActivityTypical Duration / Sample
System AuditEntire QMS Structure & Annex SL ClausesEvaluate overall compliance of policy, manual, SOPs, and management reviewReviewing company-wide Management Review, Risk Mgmt, and Internal Audit recordsBroad & High-Level (2 to 5 Days)
Process AuditSpecific Manufacturing or Administrative WorkflowVerify process inputs, controls, parameters, SOP adherence, and outputsEvaluating automated SMT soldering line parameters, thermal profiles, and operator trainingFocused Depth (1 to 2 Days per Process)
Product / Service AuditPhysical End-Item, Component, or Final ServiceVerify physical, mechanical, functional compliance against drawingsRe-inspecting finished assembly off shipping dock using calibrated gagesDeep Item Inspection (Small Batch / Lot)

Comparative Analysis of Scope

  • System Audit: Broadest scope, lowest item-level detail. Evaluates whether the management system is designed properly and operating systematically across the organization.
  • Process Audit: Moderate scope, high operational detail. Traces process steps sequentially (Turtle Diagram approach: Inputs, Hardware, Personnel, Methods, Metrics, Outputs) to ensure parameters produce conforming output.
  • Product Audit: Narrowest scope, highest physical technical detail. Evaluates the result of processes by performing independent verification on finished hardware or services.

3. ISO 19011:2018 Guidelines & Core Auditing Principles

ISO 19011 provides international guidance on managing audit programs, conducting QMS/EMS audits, and evaluating auditor competence. ISO 19011:2018 outlines seven fundamental principles that guide auditor conduct:

  1. Integrity: The foundation of professionalism. Auditors must perform work with honesty, diligence, responsibility, and observe all applicable legal and ethical requirements.
  2. Fair Presentation: The obligation to report audit findings, conclusions, and reports accurately, truthfully, and objectively. Significant obstacles or diverging opinions must be documented.
  3. Due Professional Care: The application of diligence and judgment in auditing. Auditors must exercise care proportionate to the importance of the task and the confidence placed in them.
  4. Confidentiality: Security of information. Auditors must exercise discretion in the use and protection of information acquired in the course of their duties.
  5. Independence: The basis for the impartiality of the audit and objectivity of audit conclusions. Auditors must be independent of the activity being audited wherever practicable, free from bias and conflict of interest.
  6. Evidence-Based Approach: The rational method for reaching reliable and reproducible audit conclusions in a systematic audit process. Audit evidence must be verifiable and based on samples of available information.
  7. Risk-Based Approach: An audit approach that considers risks and opportunities. Risk-based auditing significantly influences audit planning, execution, and reporting to ensure audits focus on matters of significance to the auditee.

4. Auditor Ethics, Independence, and Conflict of Interest

A critical focus of ASQ CQE certification is auditor ethics and professional objectivity.

Preventing Conflicts of Interest

  • Self-Auditing Prohibition: An auditor cannot audit a department, process, or system for which they hold operational responsibility or were directly involved in designing within a recent timeframe (typically within the last 12 months).
  • Financial & Personal Bias: Auditors must disclose any commercial, financial, or personal relationships with the auditee (e.g., holding stock in a supplier being audited during a 2nd party assessment).
  • Consulting vs. Auditing Boundary: A 3rd party registrar auditor cannot provide specific design or implementation consulting services to an auditee and subsequently audit that same organization for certification.
Loading diagram...
Classification Matrix of Quality Audits
Test Your Knowledge

An internal quality engineer is assigned to audit the final assembly department where they served as the primary process engineer three months ago. According to ISO 19011 principles, how should the engineer respond?

A
B
C
D
Test Your Knowledge

Which type of audit evaluates the physical characteristics and dimensional conformance of finished hardware immediately prior to shipment to a customer?

A
B
C
D
Test Your Knowledge

A 2nd party audit is best defined by which of the following scenarios?

A
B
C
D