9.1 Initiating the Audit, Team Roles & Feasibility Determination

Key Takeaways

  • Under ISO 19011 Clause 6.2, audit responsibility remains with the designated audit team leader from initial contact through to the completion of the audit.
  • Audit feasibility must be established based on sufficient and appropriate information, adequate cooperation from the auditee, and adequate time and resources; if unfeasible, an alternative must be proposed to the client.
  • Audit team composition must balance technical discipline competence, sector familiarity, and strict impartiality, delineating distinct roles for auditors, technical experts, observers, guides, and interpreters.
  • ISO/IEC 17021-1 strictly enforces a two-year (24-month) cooling-off period prohibiting any auditor from evaluating a management system for which they provided consultancy or internal audits.
  • Technical experts and observers cannot act as auditors, cannot question auditees without an auditor present, and have no authority to evaluate or issue audit findings.
Last updated: September 2026

9.1 Initiating the Audit, Team Roles & Feasibility Determination

Lead Auditor Core Concept: An audit is neither an informal site inspection nor an open-ended investigation. Under ISO 19011:2018 Clause 6.2 and ISO/IEC 17021-1:2015, initiating an audit represents a formal, legally grounded governance process. The Audit Team Leader assumes direct operational responsibility for determining whether an audit can achieve its objectives before significant resources are deployed. If foundational cooperation is absent, if documented information is withheld, or if conflicts of interest compromise impartiality, the Lead Auditor must take decisive action—including declaring the audit unfeasible.


1. Initiating the Audit (ISO 19011 Clause 6.2)

The audit process begins when the audit program manager or certification body designates an Audit Team Leader (Lead Auditor) and assigns responsibility for conducting the specific audit engagement. Under ISO 19011 Clause 6.2.1, overall responsibility for conducting the audit remains with the designated Audit Team Leader until the final report is distributed and all post-audit follow-up activities are finalized.

Establishing Initial Contact (Clause 6.2.2)

Initial contact with the auditee's representatives may be formal or informal, but it must be established by the Audit Team Leader or audit program manager to accomplish nine mandatory objectives:

  1. Establish Communication Channels: Identify designated organizational liaisons, authorized management representatives, and worker health and safety representatives.
  2. Confirm Authority to Audit: Validate the contractual basis, accreditation mandate, or legal authority empowering the audit team to conduct the evaluation.
  3. Provide Core Audit Details: Communicate proposed audit objectives, scope, criteria, methodology, schedule, and team composition.
  4. Request Information Access: Secure preliminary documented information needed for planning (e.g., OH&S manuals, hazard identification registers, facility plot plans, legal registers, and internal audit reports).
  5. Determine Applicable Safety and Security Rules: Identify site-specific Occupational Health and Safety (OH&S) entry requirements, mandatory Personal Protective Equipment (PPE), security clearance protocols, and facility access restrictions.
  6. Make Logistical Arrangements: Coordinate meeting rooms, secure workspaces, communications technology, escort guides, and travel arrangements.
  7. Agree on Attendance of Observers and Guides: Clarify the presence of trainee auditors, accreditation witnesses, client observers, and the assignment of organizational guides.
  8. Determine Specific Site Concerns: Identify high-hazard operational areas, ongoing shutdowns, construction projects, or labor disputes that could impact auditor safety or audit scheduling.
  9. Resolve Initial Objections: Address any client concerns regarding team composition, scheduling conflicts, or proprietary trade secret confidentiality.

2. Determining Audit Feasibility (ISO 19011 Clause 6.2.3)

An audit cannot be conducted on mere faith that necessary evidence will materialize. ISO 19011 Clause 6.2.3 mandates that the Audit Team Leader explicitly evaluate whether the audit is feasible based on three cumulative criteria:

                      ┌──────────────────────────────────────────────┐
                      │          AUDIT FEASIBILITY TRIAD             │
                      └──────────────────────┬───────────────────────┘
                                             │
             ┌───────────────────────────────┼───────────────────────────────┐
             ▼                               ▼                               ▼
┌─────────────────────────┐     ┌─────────────────────────┐     ┌─────────────────────────┐
│ 1. Information          │     │ 2. Cooperation          │     │ 3. Time & Resources     │
│ Sufficient & appropriate│     │ Adequate access to      │     │ Adequate audit days,    │
│ documented information  │     │ facilities, personnel,  │     │ qualified auditors &    │
│ to plan and conduct.    │     │ records, and workers.   │     │ technical specialists.  │
└─────────────────────────┘     └─────────────────────────┘     └─────────────────────────┘

The Three Mandatory Feasibility Criteria

  1. Sufficient and Appropriate Information: The auditee must provide adequate documentation of its OH&S management system—including hazard identification records, operational procedures, legal registers, and performance data—to enable the audit team to understand the organization and plan verification activities.
  2. Adequate Cooperation from the Auditee: The organization must commit to providing unrestricted physical and virtual access to operating facilities, documentation, records, management representatives, and non-managerial frontline workers (Clause 5.4).
  3. Adequate Time and Resources: The audit team must have sufficient audit duration (audit days calculated per IAF MD 5), proper logistical support, and access to competent personnel to evaluate the defined scope.

Action Required When an Audit Is Not Feasible

If any of the three feasibility conditions are not met, the Audit Team Leader must immediately inform the audit client. In consultation with the client, the Audit Team Leader must propose an alternative action, which may include:

  • Rescheduling the audit to allow the auditee to complete missing documentation or resolve access barriers;
  • Re-scoping the audit (e.g., modifying boundaries or excluding inaccessible non-operational sites, provided exclusions conform to ISO/IEC 17021-1);
  • Transitioning part of the audit to remote evaluation techniques if physical site access is temporarily compromised (per IAF MD 4);
  • If no viable alternative can be agreed upon, formally cancelling or halting the audit engagement. The auditor must never conduct a superficial audit that compromises audit integrity.

3. Selecting the Audit Team and Defining Roles (ISO 19011 Clause 6.2.4)

Selecting an audit team requires balancing overall team competence against the operational risks and technological complexities of the auditee's processes. The team must collectively possess knowledge of ISO 45001:2018, applicable occupational health and safety statutory regulations, sector-specific hazard profiles (e.g., chemical processing, heavy manufacturing, mining), and management system auditing principles.

Audit RolePrimary Operational FunctionAudit Finding AuthorityMandatory Boundaries & Exam Pitfalls
Audit Team Leader (Lead Auditor)Manages the audit engagement, directs team members, coordinates with client leadership, chairs opening/closing meetings, and finalizes the audit report.Full authority to issue nonconformities and make certification recommendations.Responsible for all team decisions; cannot delegate final reporting authority or dispute resolution to client personnel.
Team AuditorConducts assigned audit investigations, examines documented information, observes operations, interviews workers, and drafts audit findings.Authorized to formulate audit findings under the supervision of the Team Leader.Must remain strictly within assigned scope; must not evaluate areas where personal conflicts of interest exist.
Technical ExpertProvides specialized technical knowledge on specific equipment, processes, toxic chemicals, or local safety legislation.NO authority to act as an auditor, interview personnel independently, or issue findings.Must always be accompanied by a qualified auditor; acts strictly as an advisor to the audit team; cannot be counted as an auditor for audit-day calculations.
ObserverTrainee auditors gaining experience, accreditation body assessors (witness auditors), or client representatives.NO authority to audit, question personnel, or influence findings.Must not participate in interviews, challenge auditee staff, or disrupt audit proceedings. Must observe confidentiality.
GuideAppointed by the auditee to facilitate site navigation, ensure visitor safety, arrange interviews, and witness evidence gathering.NO authority to answer audit questions or defend system failures.Cannot answer interview questions on behalf of workers; cannot steer auditors away from problematic or high-hazard operating areas.
InterpreterProvides neutral, accurate linguistic translation between the audit team and auditee personnel.NO authority to interpret standard requirements or offer technical opinions.Must translate statements verbatim without filtering, embellishing, or advising either party.

4. Addressing Conflict of Interest and Impartiality (ISO/IEC 17021-1 Clause 5.2)

Impartiality is the bedrock of third-party conformity assessment. ISO/IEC 17021-1 Clause 5.2 mandates that certification bodies identify, analyze, and manage all threats to impartiality arising from auditing activities, commercial relationships, or individual auditor backgrounds.

Key Threats to Impartiality

  1. Self-Interest Threats: Financial dependence on the client, owning shares in the auditee corporation, or seeking future employment.
  2. Self-Review Threats: Auditing an OH&S management system that the auditor previously designed, documented, or implemented.
  3. Familiarity Threats: Overly close personal relationships with client executives or safety directors developed through prolonged social or business contact.
  4. Intimidation Threats: Client threats to terminate certification contracts, replace the certification body, or initiate litigation if nonconformities are issued.

The Mandatory Two-Year Cooling-Off Rule

Under ISO/IEC 17021-1 Clause 5.2.10, certification bodies are strictly prohibited from utilizing personnel who have provided management system consultancy—including internal audits, risk assessment design, or system documentation—to participate in audit or certification activities for that client for a minimum period of two years (24 months) following the conclusion of the consultancy.

Exam Watchpoint: A candidate frequently encounters questions where an auditor claims: "I wrote their safety manual 18 months ago, but since I am only participating as a technical specialist and will not write nonconformities, my participation is permitted." This is strictly prohibited. The two-year cooling-off rule applies universally across all audit team capacities.


5. Assigning Responsibilities to Team Members (ISO 19011 Clause 6.2.5)

The Audit Team Leader, in consultation with the team, allocates responsibility to each team member for auditing specific processes, functions, operational sites, or standard clauses. Work assignments must consider:

  • The individual competence, technical qualifications, and language capabilities of each auditor;
  • The independent, objective perspective required for each operational area (auditors must never audit their own previous work or departments where recent professional affiliations exist);
  • The effective utilization of resources across simultaneous operational activities (e.g., assigning one auditor to high-hazard chemical synthesis while another audits executive management review and worker consultation);
  • Periodic reallocation of assignments during multi-day audits to ensure balanced perspective and prevent auditor fatigue.

6. Real-World Audit Scenario: The Conflicted Expert & The Inaccessible Terminal

Audit Context: An international certification body is preparing an initial ISO 45001 certification audit for a deep-water marine petroleum terminal handling liquefied petroleum gas (LPG) and refined distillates. The Audit Team Leader conducts feasibility verification and audit team assembly.

Investigation & Unfolding Challenges:

  1. Feasibility Barrier: During initial contact, terminal management states that due to ongoing contract negotiations with marine dockworkers, the audit team will not be permitted to enter the jetty transfer berths or interview loading technicians. Management insists the audit team restrict their evaluation to the corporate office, safety policies, and training slide decks.
  2. Team Assembly Conflict: The certification body assigns Dr. Aris as the technical expert for cryogenic LPG handling systems. During the team briefing, Dr. Aris discloses that 14 months prior, his independent consulting firm was contracted by the terminal to conduct their quantitative hazard identification study and design their emergency release interlock protocols.

Lead Auditor Determination & Action:

  • Feasibility Resolution: The Lead Auditor informs the client that refusing access to the jetty berths and prohibiting worker interviews undermines core requirements of Clause 6.2.3 and Clause 5.4. The audit cannot achieve its objectives without evaluating high-hazard transfer operations. The Lead Auditor formally declares the audit not feasible in its current form, notifying the audit client that Stage 2 must be postponed until unrestricted access and worker cooperation are guaranteed.
  • Impartiality Resolution: The Lead Auditor immediately removes Dr. Aris from the audit team. Under ISO/IEC 17021-1 Clause 5.2.10, Dr. Aris's consultancy within the preceding 24 months creates an insurmountable self-review threat. The certification body must appoint an independent technical expert with zero consulting history with the client.

7. Common Exam Traps and Candidate Errors

  • Trap 1: Believing Technical Experts Can Issue Nonconformities. Technical experts possess subject-matter knowledge but are not qualified auditors. They cannot question auditees without an auditor present, nor can they independently write or issue audit findings. Any nonconformity identified through a technical expert's observation must be verified and issued by a qualified auditor.
  • Trap 2: Allowing Guides to Answer Interview Questions. When an auditor asks an operator on the shop floor about confined space entry procedures, the accompanying guide often jumps in to explain the process. A competent Lead Auditor must politely intervene, reminding the guide that the interview is intended to assess the worker's operational competence and awareness, not the guide's knowledge.
  • Trap 3: Waiving the 2-Year Cooling-Off Period via Client Consent. Candidates often believe that if an auditee signs a conflict-of-interest waiver, an auditor who consulted for them 12 months ago can participate. Client consent never waives ISO/IEC 17021-1 impartiality mandates. The 24-month ban is absolute.
  • Trap 4: Proceeding With an Unfeasible Audit to "Be Helpful." An auditor who initiates an audit despite missing legal registers, withheld accident logs, or prohibited site access commits a critical professional error. Audits must be halted or re-scoped; proceeding compromises the validity of the entire certification system.
Loading diagram...
ISO 19011 Clause 6.2 Audit Initiation, Feasibility & Team Formation Framework
Test Your Knowledge

During the initial audit feasibility determination under ISO 19011 Clause 6.2.3 for an upcoming ISO 45001 certification audit, the audit team leader discovers that the auditee has refused access to its high-hazard chemical synthesis reactor building and cannot provide occupational exposure monitoring data for the past twelve months. How must the audit team leader proceed?

A
B
C
D
Test Your Knowledge

A certification body is assembling an audit team for an initial ISO 45001 certification of a structural steel fabrication company. Senior auditor Marcus conducted an extensive 6-month consulting project for the same company 18 months ago, developing their hazard identification procedures and legal registers. Under ISO/IEC 17021-1 impartiality requirements, how must the certification body handle Marcus's assignment?

A
B
C
D
Test Your Knowledge

During an on-site audit of a high-voltage electrical substation, an electrical engineering technical expert assigned to the audit team observes an ungrounded transformer rack that presents an immediate electrocution hazard. What is the correct procedural role and authority of the technical expert in this situation under ISO 19011?

A
B
C
D