4.2 Audit Types (1st, 2nd, 3rd Party) and Audit Scope, Criteria & Objectives
Key Takeaways
- Audits are categorized by stakeholder relationship: first-party (internal audits for management review and self-declaration), second-party (supplier/vendor audits by interested parties), and third-party (independent certification or statutory audits).
- Audit Objectives define what the audit is intended to accomplish, Audit Scope defines the physical, organizational, and operational boundaries, and Audit Criteria provide the reference standards and requirements against which evidence is evaluated.
- Audit Evidence consists of verifiable records, statements of fact, or observations; when evaluated against Audit Criteria, it generates Audit Findings (conformity, nonconformity, or opportunity for improvement).
- Audit Conclusions represent the final holistic determination formulated by the audit team after evaluating all audit findings against the established audit objectives.
- Third-party audits are governed by ISO/IEC 17021-1, requiring rigorous institutional impartiality, formal certification processes, and multi-year surveillance cycles not required in first- or second-party audits.
4.2 Audit Types (1st, 2nd, 3rd Party) and Audit Scope, Criteria & Objectives
Quick Answer: Management systems audits are classified by the relationship between the auditor and auditee: First-party (internal audits for self-assessment), Second-party (customer audits of suppliers/contractors), and Third-party (independent certification or regulatory audits). Every audit requires three foundational pillars before fieldwork begins: Objectives (why we audit), Scope (boundaries and extent), and Criteria (the standards and rules used as reference benchmarks).
1. Classification of Audit Types
In professional environmental auditing, recognizing the type of audit is vital because each type dictates the auditor's legal authority, reporting audience, independence constraints, and the consequences of identified nonconformities.
[ Management System Audits ]
│
┌─────────────────────────────┼─────────────────────────────┐
▼ ▼ ▼
[ 1st-Party Audits ] [ 2nd-Party Audits ] [ 3rd-Party Audits ]
• Internal audits • Supplier / vendor audits • Certification bodies
• Self-assessment • Contractor evaluations • Regulatory enforcement
• Inputs to Clause 9.3 • Supply chain risk review • ISO/IEC 17021-1 governance
First-Party Audits (Internal Audits)
First-party audits are conducted by, or on behalf of, the organization itself for internal purposes.
- Key Purpose: To determine whether the EMS conforms to the organization's own arrangements, meets the requirements of ISO 14001:2015, and is effectively implemented and maintained (Clause 9.2).
- Primary Audience: Internal leadership and process owners; serves as a direct input to top management review (Clause 9.3).
- Independence Standard: Auditors must be independent of the specific activity being audited wherever practicable, but they remain employees or internal contractors of the company.
- Consequences: Internal nonconformities lead to internal corrective actions (Clause 10.2). They do not directly threaten external certification unless systematic neglect is uncovered during later external surveillance.
Second-Party Audits (External Supplier / Contractor Audits)
Second-party audits are conducted by parties having an interest in the organization, such as customers, commercial clients, or parent corporations, or by external service providers acting on their behalf.
- Key Purpose: To assess the environmental capability, regulatory compliance, and risk controls of critical suppliers, outsourced service providers, or joint venture partners (Clause 8.1 operational control over outsourced processes).
- Typical Scenarios: Auditing a licensed hazardous waste disposal contractor's incineration facility; auditing an outsourced chrome plating vendor to ensure heavy metal wastewater is not dumped into public sewer lines.
- Independence Standard: The auditor represents the purchasing organization and must be independent of the supplier.
- Consequences: Major nonconformities can lead to contract termination, disqualification from approved vendor lists (AVL), or financial penalties.
Third-Party Audits (Independent Certification, Accreditation & Regulatory Audits)
Third-party audits are conducted by independent, external auditing organizations, completely detached from any commercial interest in the auditee.
- Certification / Registration Audits: Conducted by accredited Certification Bodies (CBs) / Registrars operating under ISO/IEC 17021-1. Successful completion results in accredited ISO 14001 certification.
- Accreditation Audits: Conducted by national accreditation bodies (e.g., UKAS, ANAB, DAkkS) auditing the certification bodies themselves to verify compliance with ISO/IEC 17021-1.
- Statutory / Regulatory Inspections: Conducted by environmental protection agencies (e.g., US EPA, UK Environment Agency) under legislative mandates to enforce environmental permits and statutory discharge standards.
- Independence Standard: Absolute independence; strict prohibition on consulting, past employment within two years, or shared financial interests.
- Consequences: Major nonconformities block certification or result in certificate suspension; regulatory audits can trigger criminal prosecution, stop-work orders, or statutory fines.
2. Contrast Table: 1st, 2nd, and 3rd Party Audits
| Dimension | 1st-Party (Internal) | 2nd-Party (Supplier/Customer) | 3rd-Party (Certification) |
|---|---|---|---|
| Primary Objective | Verify internal conformance, identify improvements, prepare for management review. | Evaluate supplier risk, verify contractual/environmental controls, approve vendor. | Determine conformity with ISO 14001 for certificate issuance, maintenance, or renewal. |
| Governing Standard | ISO 14001 Clause 9.2; ISO 19011 guidance. | Commercial contracts, customer codes of conduct, ISO 19011 guidance. | ISO/IEC 17021-1; ISO 14001; IAF Mandatory Documents; ISO 19011. |
| Auditor Independence | Internal independence from unit audited; internal peer review. | Independent of the supplier being audited; acts on buyer's behalf. | Absolute commercial, legal, and operational independence from auditee. |
| Report Recipient | Internal Top Management, EHS Committee, auditee process owners. | Purchasing Director, Corporate Sustainability, Supply Chain VP. | Certification Committee / Impartiality Board of the Certification Body. |
| Impact of Major Nonconformity | Corrective action issued; root-cause fix reviewed at management review. | Supplier suspension, contract withholding, loss of preferred vendor status. | Certification refused, suspended, or withdrawn; mandatory on-site re-audit. |
| Auditor Legal Liability | Internal employment accountability. | Governed by commercial contract terms and non-disclosure agreements. | Strict professional liability, ISO/IEC 17021-1 accreditation oversight. |
3. The Core ISO 19011 Auditing Terminology
To conduct and document audits defensibly, lead auditors must master the hierarchical relationships between objectives, scope, criteria, evidence, findings, and conclusions:
[ Audit Objectives ] ──► Why we audit (purpose and desired outcomes)
[ Audit Scope ] ──► Where and what we audit (boundaries, units, time)
[ Audit Criteria ] ──► What we measure against (standards, permits, rules)
│
▼
[ Audit Evidence ] ──► Verifiable facts, records, observations collected
│ (Evaluated against Criteria)
▼
[ Audit Findings ] ──► Conformity, Nonconformity (Major/Minor), OFI
│ (Synthesized against Objectives)
▼
[ Audit Conclusions] ──► Final outcome (recommendation regarding certification)
The Framing Triad: Objectives, Scope, and Criteria
-
Audit Objectives (set under ISO 19011:2018 Clause 5.4.2; not a defined term in Clause 3): Describe what the audit is intended to accomplish. Typical EMS objectives include:
- Determining the degree of conformity of the management system with ISO 14001:2015.
- Evaluating the capability of the EMS to ensure compliance with statutory environmental permits.
- Evaluating the effectiveness of the EMS in achieving specified environmental performance targets.
- Identifying areas for potential improvement.
-
Audit Scope (ISO 19011:2018 Clause 3.5): Defines the extent and boundaries of the audit. It includes:
- Physical locations: Physical boundaries (e.g., "The chemical manufacturing plant at 100 Industrial Boulevard, excluding the decommissioned North Annex").
- Organizational units: Departments, functions, and divisions included.
- Activities and processes: Specific manufacturing lines, shipping docks, on-site effluent treatment plants.
- Time period covered: Time window of records sampled (e.g., "Operational records generated between October 1, 2025, and September 1, 2026").
- Note: The audit scope must be consistent with, or nested within, the overall EMS scope defined under ISO 14001:2015 Clause 4.3.
-
Audit Criteria (ISO 19011:2018 Clause 3.7): The reference against which audit evidence is compared. Criteria serve as the benchmark for determining conformity. In an EMS audit, criteria include:
- The clauses of ISO 14001:2015.
- Applicable environmental legislation, statutory discharge consents, and air emissions operating permits.
- The organization's documented policies, standard operating procedures (SOPs), and emergency plans.
- Customer-specific EHS specifications or corporate environmental guidelines.
The Evaluation Chain: Evidence, Findings, and Conclusions
- Audit Evidence (Clause 3.9): Records, statements of fact, or other information that are relevant to the audit criteria and verifiable. Evidence is obtained through interviews, physical observations, equipment readings, and sampling of documents and records. Hearsay and unverified assumptions are not audit evidence.
- Audit Findings (Clause 3.10): Results of evaluating the collected audit evidence against the audit criteria. Findings indicate either conformity or nonconformity (graded as Major or Minor) with the audit criteria, or opportunities for improvement (OFI).
- Audit Conclusions (Clause 3.11): The final outcome of an audit delivered by the audit team after considering the audit objectives and all audit findings. In a third-party audit, the conclusion states whether the EMS meets the standard sufficiently to recommend initial certification, maintain certification, or require a follow-up verification audit.
4. Realistic Lead Auditor Scenario: Integrated Supplier Audit
Scenario: A multinational consumer electronics corporation engages a lead auditor to conduct a second-party audit of a primary lithium-ion battery cell supplier.
- Audit Objective: Evaluate whether the supplier's EMS adequately controls heavy metal discharge risks to prevent brand reputation damage and ensure compliance with the customer's Supplier Environmental Code.
- Audit Scope: The battery electrode coating facility and wastewater treatment plant located in Facility B; covers operations and compliance records from the preceding 12 months.
- Audit Criteria: ISO 14001:2015, the Customer's Supplier Environmental Code (Revision 4.0), and Local Environmental Discharge Consent #EV-9021.
Investigation Trail:
- Evidence Gathered: The auditor samples daily discharge logs for heavy metals (nickel and cobalt) from the wastewater plant. On 8 out of 90 operational days, cobalt concentrations were recorded at 1.8 mg/L, exceeding the local statutory consent limit of 1.0 mg/L (Audit Evidence).
- Evaluation Against Criteria: The evidence is evaluated against Consent #EV-9021 (Clause 4.1) and ISO 14001:2015 Clause 9.1.2 (Compliance Evaluation). The supplier logged no incident report, notified no regulator, and initiated no corrective action.
- Audit Finding Generated: A Major Nonconformity against ISO 14001:2015 Clause 9.1.2 and Clause 10.2: Failure to maintain compliance with statutory consent limits and failure to react to non-compliances with corrective action.
- Audit Conclusion Formulated: The audit team concludes that while the manufacturing processes are modern, operational controls over wastewater abatement are ineffective. Recommendation to the client: Place the supplier on conditional probation with mandatory re-audit within 60 days before awarding high-volume production contracts.
5. CQI/IRCA Exam Traps: Scope, Criteria, and Findings
- Confusing Scope with Criteria: A classic exam error occurs when candidates list "ISO 14001:2015" under Audit Scope. ISO 14001 is the Audit Criteria (the rulebook). The Audit Scope is the physical site, processes, and operational boundaries being audited.
- Confusing Findings with Conclusions: Stating that "The audit conclusion is that the company has three minor nonconformities" is incorrect. The three nonconformities are the Audit Findings. The Audit Conclusion is the holistic synthesis: "The EMS is implemented effectively and demonstrates continuous improvement; recommendation is granted for ISO 14001 certification subject to acceptable corrective action plans."
- Scope Creep: An auditor inspecting a certified warehouse observes an uncertified adjacent metal plating facility owned by the same parent company. The auditor cannot issue formal nonconformities against the plating facility unless the audit client and auditee formally expand the agreed Audit Scope.
An audit team begins a Stage 2 certification audit of an industrial foundry. Before inspecting the molding line, the lead auditor reviews the facility's air operating permit, the corporate environmental manual, and ISO 14001:2015. In ISO 19011 terminology, what do these reference documents represent?
A major retail brand hires an independent environmental auditing firm to audit the wastewater treatment practices of an offshore denim dyeing mill before placing a supply contract. What category of audit is being performed?
During audit preparation, the lead auditor documents: 'The audit will evaluate the precision machining and surface finishing lines at the Manchester plant, covering production records and emissions data between January 2025 and December 2025.' Which audit component has the lead auditor defined?
At the conclusion of a five-day third-party recertification audit, the audit team synthesizes thirty audit findings (twenty-eight conformities and two minor nonconformities) and determines that the EMS achieves its intended outcomes and warrants renewal of the ISO 14001 certificate. What term defines this final collective determination?