7.1 Audit Definition & First/Second/Third-Party Audits

Key Takeaways

  • An audit is a systematic, independent, and documented process for obtaining objective evidence and evaluating it objectively to determine the extent to which audit criteria are fulfilled
  • First-party audits are internal; second-party audits are conducted by interested parties such as customers; third-party audits are independent certification or regulatory audits
  • Independence means freedom from bias that could affect objectivity — internal auditors must still be independent of the activities they audit
  • ISO 14001 certification audits are typically third-party audits performed by accredited certification bodies against ISO 14001 requirements
  • Lead auditors must correctly classify audit type because it drives who sets objectives, who receives the report, and how findings are used
Last updated: July 2026

7.1 Audit Definition & First/Second/Third-Party Audits

Quick Answer: An audit is a systematic, independent, and documented process for obtaining objective evidence and evaluating it to determine how well audit criteria are fulfilled. In EMS work you will run or face first-party (internal), second-party (customer/supplier), and third-party (certification/regulatory) audits — and each type changes who commissions the audit, how independent the team must be, and what happens with findings.

Understanding the definition of an audit — and who performs it — is foundational for ISO 14001 Lead Auditor candidates. Exam questions often test whether you can distinguish audit types, apply independence correctly inside an organization, and recognize that “independent” does not always mean “external.”

What Is an Audit?

ISO 19011 defines an audit as a systematic, independent, and documented process for obtaining objective evidence and evaluating it objectively to determine the extent to which the audit criteria are fulfilled.

Break that definition into its working parts:

ElementMeaning in practice
SystematicPlanned and executed using a defined method (programme, plan, checklist, sampling strategy) — not a casual walk-through
IndependentFree from bias and conflict of interest that could compromise objectivity
DocumentedPlans, evidence, findings, and reports are recorded so results are reproducible and defensible
Objective evidenceRecords, statements of fact, or other information that are relevant to the criteria and verifiable
Audit criteriaSet of policies, procedures, or requirements used as a reference (e.g., ISO 14001 clauses, legal requirements, EMS procedures)

An EMS audit is therefore not a consulting visit, a training session, or a management review. Consulting improves the system; auditing evaluates conformity and effectiveness against agreed criteria. Confusing those roles undermines independence and can invalidate certification audit conclusions.

Audit vs. Related Activities

Lead auditors should keep these distinctions clear:

  • Inspection — typically verifies a product, service, or condition against a specification at a point in time.
  • Surveillance — ongoing monitoring; may feed evidence into an audit but is not itself a full audit cycle.
  • Assessment / evaluation — broader terms; in certification contexts, “assessment” often means the certification body’s evaluation activities, which include audits.
  • Gap analysis — often advisory; useful before certification, but not a substitute for an independent conformity audit.

First-Party Audits (Internal Audits)

A first-party audit is conducted by, or on behalf of, the organization itself for internal purposes. ISO 14001 clause 9.2 requires internal audits at planned intervals to provide information on whether the EMS conforms to the organization’s own requirements and to ISO 14001, and whether it is effectively implemented and maintained.

Typical first-party EMS examples:

  • Annual internal audit of operational controls for hazardous waste storage
  • Process audit of emergency preparedness drills against the organization’s own procedure
  • Multi-site internal audit programme covering significant environmental aspects across plants

Independence in first-party audits: Internal auditors should not audit their own work. A plant environmental coordinator who wrote the spill-response procedure should not be the sole auditor of that procedure’s implementation. Organizations often rotate auditors across departments, use corporate EMS auditors for site audits, or engage external contractors acting on behalf of the organization (still first-party if the organization owns the audit purpose and report).

First-party audit outputs usually go to top management and process owners. Findings drive corrective action, management review inputs, and continual improvement — not a certificate decision by an outside body.

Second-Party Audits

A second-party audit is conducted by parties having an interest in the organization, such as customers, or by other persons on their behalf. In supply-chain EMS contexts, a customer may audit a supplier’s environmental controls before awarding a contract or as ongoing supplier oversight.

Typical second-party EMS examples:

  • Automotive OEM audits a tier-1 supplier against customer-specific environmental requirements plus ISO 14001 expectations
  • Retail brand audits a packaging supplier for restricted substances and recycling claims
  • Construction client audits a contractor’s site environmental management plan before mobilization

Second-party audits are often contractual. Criteria may include ISO 14001, customer standards, and purchase-order environmental clauses. Findings can affect sourcing decisions, approved-supplier status, or corrective-action timelines written into contracts. The auditor represents the interested party’s interests, not a certification scheme.

Third-Party Audits

A third-party audit is conducted by an independent auditing organization. For ISO 14001, this typically means an accredited certification body performing Stage 1, Stage 2, surveillance, and recertification audits. Regulatory inspections by environmental agencies are also third-party in nature, though their criteria are legal requirements rather than ISO 14001 alone.

Typical third-party EMS examples:

  • Initial ISO 14001 certification audit by an accredited CB
  • Annual surveillance audit sampling EMS processes and sites
  • Regulatory compliance inspection focused on air permits and reporting

Third-party auditors must maintain independence from the auditee’s consulting relationships where scheme rules require it. Certification decisions follow defined processes; the audit team recommends, and the CB’s independent review function typically makes the certification decision.

Comparing Audit Parties

FeatureFirst-partySecond-partyThird-party
Who initiatesThe organizationInterested party (e.g., customer)Independent body (CB, regulator)
Primary purposeInternal assurance & improvementSupplier/customer confidenceCertification, accreditation, or legal compliance
Typical criteriaISO 14001 + own EMSContract + ISO/customer specsISO 14001 / scheme / law
Report goes toManagementInterested partyCB/regulator (+ auditee copy)
Independence barIndependent of audited activityIndependent of auditee operationsOrganizationally independent

Why Classification Matters for Lead Auditors

Misclassifying audit type leads to wrong planning choices. A first-party auditor who acts like a consultant blurs independence. A third-party auditor who accepts the auditee’s undocumented verbal claims without verification fails the evidence-based approach. A second-party auditor who ignores contractual environmental clauses because “ISO 14001 doesn’t require that exact control” may miss the actual audit criteria.

When you open an audit assignment, always ask: Who is the client? Who is the auditee? Who are other interested parties? What criteria apply? Those answers fix the party type and drive objectivity, reporting, and follow-up.

Combined and Joint Audits (Related Concepts)

ISO 19011 also distinguishes combined audits (two or more management systems audited together, e.g., ISO 14001 + ISO 9001) and joint audits (two or more auditing organizations cooperating). These describe how audits are delivered, not first/second/third-party status. An integrated EMS/QMS certification visit can still be a single third-party audit that is combined across standards.

For exam success, master the definition first, then map every scenario to first-, second-, or third-party before you discuss sampling, findings, or certification outcomes.

Test Your Knowledge

According to ISO 19011, which statement best defines an audit?

A
B
C
D
Test Your Knowledge

A customer audits a packaging supplier against purchase-order environmental clauses and ISO 14001 expectations before renewing a contract. What type of audit is this?

A
B
C
D
Test Your Knowledge

Which situation correctly preserves independence in a first-party EMS audit?

A
B
C
D
Test Your Knowledge

An accredited certification body performs a Stage 2 ISO 14001 audit at a manufacturing plant. How should a lead auditor classify this audit?

A
B
C
D