16.2 Internal vs External Audits & the Internal Audit Function

Key Takeaways

  • Internal audits (first-party) are required by ISO 14001 Clause 9.2; external audits include supplier (second-party) and certification/regulatory (third-party) audits
  • The internal audit function provides independent assurance that the EMS conforms to requirements and is effectively implemented and maintained
  • Objectivity and impartiality require competent auditors who do not audit their own work, even in small organizations that use creative rotation or outsourced internal auditors
  • External certification audits evaluate the EMS—including the effectiveness of the internal audit programme—but do not replace the organization’s Clause 9.2 obligation
  • Lead auditors must recognize when weak internal audits create systemic risk that surfaces as Stage 2 or surveillance findings
Last updated: July 2026

16.2 Internal vs External Audits & the Internal Audit Function

Quick Answer: Internal (first-party) audits are the organization’s own planned checks against ISO 14001 and its EMS requirements. External audits are performed by outside parties—customers or other interested parties (second-party) or independent certification/regulatory bodies (third-party). ISO 14001 Clause 9.2 mandates an internal audit programme; certification audits assess that programme but never substitute for it.

Lead Auditor candidates must navigate two vocabularies that overlap: party classification (first/second/third) and internal vs external relative to the organization. Getting them straight prevents scope errors, impartiality failures, and exam mistakes.

First-, Second-, and Third-Party Audits

TypeWho performs itTypical purpose for an EMSExample
First-party (internal)Organization’s own staff or contracted auditors acting for the organizationVerify conformity and EMS effectiveness; feed management review and improvementAnnual internal EMS audit of wastewater treatment and chemical storage
Second-partyCustomer, partner, or other interested partyAssure supplier environmental performance or contractual EMS commitmentsCustomer audits a packaging supplier’s recycling and substance-restriction controls
Third-partyIndependent body (e.g., accredited certification body)Certification, surveillance, recertification, or regulatory inspectionAccredited CB Stage 2 / surveillance against ISO 14001:2015

“External audit” usually means second- or third-party. “Internal audit” means first-party—even if the organization hires an external consultant to perform the internal audit on its behalf. In that case the consultant is an outsourced resource of the internal audit programme, not a certification auditor.

What ISO 14001 Requires of the Internal Audit Function

Clause 9.2.1 requires internal audits at planned intervals to provide information on whether the EMS:

  1. Conforms to the organization’s own EMS requirements,
  2. Conforms to ISO 14001:2015, and
  3. Is effectively implemented and maintained.

Clause 9.2.2 then requires the organization to establish, implement, and maintain the programme (frequency, methods, responsibilities, planning, reporting), define criteria and scope for each audit, select auditors to ensure objectivity and impartiality, ensure results are reported to relevant management, and retain documented information as evidence of programme implementation and audit results.

The internal audit function is therefore not a person with a title alone—it is the accountable capability that designs the programme, assigns competent auditors, protects impartiality, reports results, and drives follow-up into corrective action and management review.

Objectivity, Impartiality, and Small-Organization Reality

Auditors must not audit their own work. A plant EHS manager who authored the spill procedure should not be the sole auditor of that procedure’s implementation. Options include cross-site auditors, rotating departmental auditors with independence rules, or competent external contractors acting as first-party auditors. Competence still matters: impartiality without EMS and process knowledge produces shallow checklists. ISO 19011 guidance on auditor competence (Clause 7) and ISO 14001 Clause 7.2 together set the expectation that people performing internal audits understand environmental aspects, compliance obligations, and audit methods.

How Internal and External Audits Interact

Certification bodies treat a mature internal audit function as a key assurance mechanism. During Stage 1, auditors often sample the programme design. During Stage 2 and surveillance, they sample internal audit reports, finding quality, follow-up effectiveness, and whether high-importance processes receive adequate coverage. Common external findings include:

  • Programme that ignores environmental importance and previous results (calendar-only scheduling).
  • Auditors auditing their own departments without mitigation.
  • Reports that list only documentation presence, not effective implementation.
  • Open nonconformities with no timely corrective action or ineffective closure.
  • Missing link from internal audit results into Clause 9.3 management review inputs.

Conversely, strong internal audits reduce surprise at certification: they surface operational-control gaps early, verify legal compliance monitoring, and demonstrate continual improvement. Second-party customer audits may still probe areas outside the ISO 14001 certificate scope if contracts demand it—Lead Auditors must keep criteria clear.

Roles Relative to the Audit Programme Manager

The person managing the audit programme (internal) sets objectives, resources, and schedule. Internal auditors execute assigned audits. Process owners provide access and respond to findings. Top management receives results and ensures resources for correction. External lead auditors evaluate whether that system works—they do not “become” the internal function for the year.

Exam Distinctions to Memorize

  • Required vs optional: Internal audits are required for ISO 14001 conformity. Third-party certification is a choice (unless customers/regulators mandate it). Passing a certification audit does not eliminate Clause 9.2.
  • Independence levels differ: Third-party auditors must meet ISO/IEC 17021-1 impartiality rules. Internal auditors need objectivity within the organization’s control framework—not the same structural independence as a CB, but still no self-audit of their own work.
  • Evidence of the function: Schedules, auditor competence records, audit plans/reports, nonconformity logs, and management review minutes showing audit results were considered.

Scenario: Mislabeled “External Internal Audit”

A small electronics assembler outsources its annual EMS audit to a consultant and labels every report “third-party audit,” then tells the CB that Clause 9.2 is satisfied by certification surveillance. The Lead Auditor should recognize two errors: (1) the consultant audit, if commissioned by the organization against its EMS, is still first-party/internal programme activity; (2) CB surveillance cannot replace the organization’s planned internal audits. Correct treatment: keep the consultant under the internal programme with defined criteria/scope/impartiality, retain results as Clause 9.2 evidence, and present them—alongside other EMS performance data—at management review.

Test Your Knowledge

A manufacturing company hires an independent consulting firm to conduct its planned annual EMS audits against ISO 14001 and its own procedures. How should these audits be classified?

A
B
C
D
Test Your Knowledge

Which statement correctly describes the relationship between ISO 14001 Clause 9.2 and third-party certification audits?

A
B
C
D
Test Your Knowledge

What is the most appropriate way to protect impartiality when the only EMS expert on site also owns several audited processes?

A
B
C
D