4.2 Audit Types: First, Second, and Third-Party

Key Takeaways

  • Audits are categorized by party relationship: First-party (internal audits), Second-party (supplier/vendor audits), and Third-party (accredited certification and regulatory audits).
  • ISO/IEC 27001 Clause 9.2 mandates annual first-party internal audits to verify that the ISMS conforms to organizational requirements and standard controls.
  • The ISO/IEC 27001 certification lifecycle spans a 3-year cycle consisting of Stage 1 (readiness & document review), Stage 2 (initial operational audit), annual Surveillance audits, and a triennial Recertification audit.
  • Combined audits evaluate multiple management systems (e.g., ISO 27001 + ISO 22301) under one integrated audit team, whereas Joint audits involve two distinct auditing organizations auditing a single auditee simultaneously.
  • Remote and hybrid auditing methodologies are governed by IAF MD 4, leveraging ICT tools while recognizing limitations in physical security control verification.
Last updated: July 2026

4.2 Audit Types: First, Second, and Third-Party

In information security management, audits are conducted for diverse business reasons, ranging from internal quality control to contractual vendor governance and formal accredited certification. Understanding the classification of audits based on the relationship between the auditor, the audit client, and the auditee is fundamental to ISO/IEC 27001 Lead Auditor practice.

Audits are categorized into three primary party designations: First-Party, Second-Party, and Third-Party audits. Furthermore, third-party certification audits follow a strict 3-year lifecycle regulated by international accreditation rules (ISO/IEC 17021-1 and ISO/IEC 27006).


The Three Primary Audit Classifications

                      AUDIT CLASSIFICATION BY PARTY

┌──────────────────┐    ┌──────────────────┐    ┌──────────────────┐
│ 1st-Party Audit  │    │ 2nd-Party Audit  │    │ 3rd-Party Audit  │
│ (Internal Audit) │    │ (Supplier Audit) │    │ (Certification)  │
├──────────────────┤    ├──────────────────┤    ├──────────────────┤
│ • Self-assessment│    │ • Customer ->    │    │ • Independent    │
│ • Clause 9.2     │    │   Supplier       │    │   Certification  │
│ • Management     │    │ • Contractual /  │    │   Body (CB)      │
│   Review input   │    │   SLA checks     │    │ • ISO 17021 /    │
│                  │    │                  │    │   ISO 27006      │
└──────────────────┘    └──────────────────┘    └──────────────────┘

1. First-Party Audits (Internal Audits)

First-party audits are internal audits conducted by, or on behalf of, the organization itself for internal management review, self-assessment, and continuous improvement.

  • Requirement: ISO/IEC 27001 Clause 9.2 explicitly requires organizations to conduct internal audits at planned intervals to determine whether the ISMS conforms to the organization's own requirements and the requirements of ISO/IEC 27001.
  • Auditor Selection: Audits may be performed by internal employees or external consultants hired to execute the internal audit program. However, auditors must be independent of the specific activity being audited (e.g., an internal auditor can audit the HR department, but cannot audit the security policy they wrote).
  • Primary Purpose: To evaluate ISMS operational effectiveness, identify non-conformities before external audits, and provide objective information to Top Management for the Management Review process (Clause 9.3).

2. Second-Party Audits (External Supplier / Vendor Audits)

Second-party audits are external audits conducted by an organization on its suppliers, vendors, contractors, or outsourced service providers (or by an independent party acting on the customer's behalf).

  • Context: Second-party audits are driven by commercial interest, contractual rights, and supply chain security requirements (governed by ISO/IEC 27002:2022 Controls 5.19, 5.20, and 5.21).
  • Primary Purpose: To verify that a critical vendor adheres to contractual security commitments, Service Level Agreements (SLAs), data protection standards, and regulatory requirements before or during contract performance.
  • Key Constraint: The audit scope, criteria, and access permissions are defined strictly by the contractual audit clause agreed between customer and supplier.

3. Third-Party Audits (Accredited Certification & Regulatory Audits)

Third-party audits are independent audits conducted by external auditing organizations—such as accredited Certification Bodies (CBs) (also known as Registrars) or statutory regulatory agencies (e.g., HIPAA, GDPR, or financial regulators).

  • Governance: Certification Bodies operating ISO/IEC 27001 audit schemes must comply with ISO/IEC 17021-1 (Conformity assessment — Requirements for bodies providing audit and certification of management systems) and ISO/IEC 27006 (Requirements for bodies providing audit and certification of information security management systems).
  • Outcome: Successful completion of an accredited third-party audit leads to the issuance of a formal ISO/IEC 27001 Certificate of Conformity, which provides independent assurance to clients, regulators, and market stakeholders.

Comparison Matrix of Audit Types

DimensionFirst-Party (Internal)Second-Party (Supplier)Third-Party (Certification)
Audit ClientInternal Top ManagementPurchasing / Risk Management DeptIndependent Registrant / Client
AuditeeInternal Operations / TeamsExternal Vendor / SupplierOrganization seeking certification
Primary ObjectiveSelf-assessment & Clause 9.2 complianceSupply chain risk & SLA verificationIndependent conformity & certification
Governing StandardISO 19011 & ISO 27001 Cl 9.2Contractual terms & ISO 27002 Cl 5.19ISO/IEC 17021-1 & ISO/IEC 27006
Auditor RequirementEmployee or hire; non-self-reviewCustomer auditor or 3rd-party vendor auditorFully independent accredited CB auditor
Final DeliverableInternal Audit Report to CISO/ExecsVendor Audit Report to Vendor ManagerFormal Audit Report & ISO 27001 Certificate

The ISO/IEC 27001 Certification Audit Lifecycle (3-Year Cycle)

Accredited ISO/IEC 27001 third-party certification is not a one-time event. It follows a mandatory 3-year certification lifecycle consisting of four distinct audit phases:

                  THE 3-YEAR CERTIFICATION LIFECYCLE

   ┌─────────────────────────────────────────────────────────────┐
   │  STAGE 1 AUDIT (Document & Readiness Review)               │
   │  • Review ISMS documentation, scope, and SoA              │
   │  • Assess facility locations and Stage 2 readiness          │
   └──────────────────────────────┬──────────────────────────────┘
                                  │
                                  ▼
   ┌─────────────────────────────────────────────────────────────┐
   │  STAGE 2 AUDIT (Initial Certification Audit)                │
   │  • Evaluate operational effectiveness of all controls       │
   │  • Conduct extensive sampling, interviews, and testing       │
   │  • Certification decision issued upon NC resolution          │
   └──────────────────────────────┬──────────────────────────────┘
                                  │
                                  ▼
   ┌─────────────────────────────────────────────────────────────┐
   │  SURVEILLANCE AUDITS (Years 1 and 2)                       │
   │  • Conducted annually (Month 12 and Month 24)                │
   │  • Sample selected controls, internal audit, Mgmt Review    │
   └──────────────────────────────┬──────────────────────────────┘
                                  │
                                  ▼
   ┌─────────────────────────────────────────────────────────────┐
   │  RECERTIFICATION AUDIT (Year 3)                             │
   │  • Conducted before certificate expiry (Month 36)           │
   │  • Comprehensive audit of entire ISMS to renew certificate   │
   └─────────────────────────────────────────────────────────────┘

Phase 1: Stage 1 Audit (Document and Readiness Review)

The Stage 1 audit evaluates the organization's ISMS documentation and operational readiness for Stage 2. It is typically conducted partially on-site and partially off-site.

  • Objectives:
    • Review mandatory ISMS documentation: Scope statement, Information Security Policy, Risk Assessment methodology, Risk Treatment Plan (RTP), and Statement of Applicability (SoA).
    • Verify that the ISMS scope boundaries and physical/logical locations are clearly defined.
    • Confirm that internal audits (Clause 9.2) and Management Review (Clause 9.3) have been performed at least once.
    • Assess the auditee's understanding of ISO/IEC 27001 requirements and evaluate site-specific security conditions to plan Stage 2 resourcing.
  • Outcome: The Stage 1 report details findings and categorizes the organization's readiness. If critical document omissions exist (e.g., missing SoA), Stage 2 cannot proceed until corrective action is taken.

Phase 2: Stage 2 Audit (Initial Certification Audit)

The Stage 2 audit evaluates the operational implementation and effectiveness of the organization's ISMS controls. It must take place on-site at the organization's facilities (or virtually for documented cloud operations).

  • Objectives:
    • Test the operational effectiveness of all applicable ISO/IEC 27001:2022 Annex A controls selected in the SoA.
    • Collect evidence through employee interviews, log observation, system configuration checks, and sampling.
    • Evaluate conformity with mandatory Clauses 4 through 10.
  • Findings & Certification Decision: Any Non-Conformities (NCs) identified are graded as Major or Minor. Major NCs must be remediated and verified before certification can be granted. The certification decision is made by an independent Certification Body decision committee that was not part of the audit team.

Phase 3: Surveillance Audits (Years 1 and 2)

Certificates are valid for 3 years, contingent upon successful annual Surveillance Audits conducted at 12-month intervals (Surveillance 1 at Year 1, Surveillance 2 at Year 2).

  • Scope: Surveillance audits do not audit the entire ISMS. Instead, they cover:
    • Mandatory elements: Internal audits (Clause 9.2), Management Review (Clause 9.3), and progress on corrective actions from previous audits.
    • System maintenance, customer complaints, and scope changes.
    • A representative sample of operational Annex A security controls.

Phase 4: Recertification Audit (Year 3)

Before the 3-year certificate expires (typically around Month 36), a comprehensive Recertification Audit is conducted.

  • Scope: Evaluates the overall effectiveness of the ISMS over the full 3-year cycle, reviewing performance trends, continuous improvement, and all clauses/controls. Successful recertification issues a new 3-year certificate.

Specialized Audit Configurations

In addition to single-standard audits, Lead Auditors frequently encounter specialized audit structures:

Combined Audits

A Combined Audit occurs when an audit team evaluates an auditee against two or more management system standards simultaneously (e.g., auditing ISO/IEC 27001 [ISMS] together with ISO 22301 [Business Continuity Management] and ISO 9001 [Quality Management]).

  • Advantages: Dramatically reduces audit costs, eliminates duplicated interviews for common clauses (like Leadership, Document Control, and Management Review), and minimizes disruption to auditee operations.
  • Requirement: The audit team must possess combined auditor competence across all audited standards.

Joint Audits

A Joint Audit occurs when two or more independent auditing organizations collaborate to audit a single auditee.

  • Example: A national financial regulator and an accredited ISO Certification Body conducting a joint security assessment of a central bank service provider.
  • Challenge: Requires careful harmonization of audit plans, lead auditor authority, evidence sharing, and dispute resolution mechanisms between the different auditing bodies.

Audit Delivery Methods: On-Site, Remote, and Hybrid Auditing

Under IAF MD 4 (IAF Mandatory Document for the Use of Information and Communication Technology (ICT) for Auditing/Assessment Purposes), certification bodies may utilize remote auditing techniques.

  • On-Site Audits: Traditional physical presence. Essential for verifying physical security controls (ISO 27002 Controls 7.1–7.14), perimeter barriers, clean desk policy compliance, and datacenter hardware security.
  • Remote (Virtual) Audits: Conducted using screen sharing, video walkthroughs, document portals, and remote interview software. Highly effective for evaluating cloud architectures, policy documentation, and log reviews.
  • Hybrid Audits: Combines remote document review and technical interviews with targeted on-site physical inspections, maximizing efficiency while maintaining audit integrity.

Real-World Audit Scenario: Managing Stage 1 to Stage 2 Transition

Scenario: CloudShield Technologies, a SaaS vendor, contracts an accredited Certification Body for ISO/IEC 27001 certification. The Lead Auditor conducts the Stage 1 audit in June.

Stage 1 Audit Discovery: During Stage 1, the Lead Auditor discovers that while CloudShield has written an Information Security Policy and performed a risk assessment, their Statement of Applicability (SoA) fails to document the justification for excluding physical perimeter controls (Control 7.1 and 7.2). Furthermore, CloudShield has not yet conducted an internal audit (Clause 9.2).

Lead Auditor Decision: The Lead Auditor issues a Stage 1 Area of Concern report stating that CloudShield is not ready for Stage 2. The Lead Auditor informs management that Stage 2 cannot be scheduled until CloudShield:

  1. Updates the SoA to include clear technical justifications for all control exclusions.
  2. Executes a full internal audit across all ISMS processes and presents the internal audit report.

Two months later, CloudShield submits the revised SoA and completed internal audit records. The Lead Auditor reviews the evidence, confirms readiness, and approves scheduling the Stage 2 on-site audit for September.


PECB Exam Traps & Key Takeaways

[!WARNING] PECB Exam Trap 1: Stage 1 Operational Testing Misconception PECB questions often try to trick candidates into thinking Stage 2 is just a document review. Remember: Stage 1 is the Document & Readiness Review. Stage 2 is the operational effectiveness audit where deep sampling and evidence testing occur.

[!WARNING] PECB Exam Trap 2: Combined vs. Joint Audit Definitions Do not confuse these terms! A Combined Audit is one audit team auditing multiple standards for one auditee. A Joint Audit is multiple auditing organizations auditing one auditee.

[!TIP] PECB Exam Tip: Internal Audit Independence For 1st-party (internal) audits, auditors CAN be company employees. They do not have to be external third parties. The key rule is that they must not audit their own work.

Test Your Knowledge

Which of the following activities takes place during an ISO/IEC 27001 Stage 1 certification audit?

A
B
C
D
Test Your Knowledge

An organization successfully achieves ISO/IEC 27001 certification in January 2026. What is the mandatory audit requirement for maintaining certification in January 2027 and January 2028?

A
B
C
D
Test Your Knowledge

An audit team is evaluating a company simultaneously against ISO/IEC 27001 (Information Security) and ISO 22301 (Business Continuity Management). What type of audit configuration is this?

A
B
C
D
Test Your Knowledge

Under ISO/IEC 27001 Clause 9.2, which rule governs auditor selection for internal (first-party) audits?

A
B
C
D