Section 3.1: Audit Types, Objectives, and Scope
Key Takeaways
- First-party audits are internal audits conducted by the organization itself to check QMS health and conformity to Clause 9.2.
- Second-party audits are supplier audits conducted by a customer or a third party on their behalf to assess compliance with contracts.
- Third-party audits are external audits conducted by accredited certification bodies to determine eligibility for certification under ISO/IEC 17021-1.
- Audit scope defines the boundaries of the audit (locations, processes, products), criteria defines the standard of comparison (requirements, SOPs), and the plan is the timetable.
- Audit objectives answer why the audit is conducted and must be agreed upon by the lead auditor and client before planning.
Section 3.1: Audit Types, Objectives, and Scope
Audits are systematic, independent, and documented processes used to gather objective evidence and evaluate it against established audit criteria. In the context of ISO 9001:2015, understanding the different configurations of audits, their underlying objectives, and the critical parameters that define them—such as scope and criteria—is essential for any lead auditor. The ISO 19011:2018 guidelines and ISO/IEC 17021-1 standards provide the framework for these activities.
The Three Classifications of Audits
Audits are classified into three distinct categories based on the relationship between the auditing organization and the auditee: first-party, second-party, and third-party.
First-Party Audits (Internal Audits)
First-party audits are conducted by, or on behalf of, the organization itself for internal purposes. They are commonly referred to as internal audits. ISO 9001:2015 Clause 9.2 explicitly mandates that organizations conduct internal audits at planned intervals.
- Primary Objective: To verify whether the Quality Management System (QMS) conforms to the organization's own requirements, the requirements of ISO 9001, and that it is effectively implemented and maintained.
- Key Characteristic: While the auditor is an employee or an external consultant hired by the organization, they must maintain objectivity and impartiality. This means internal auditors must not audit their own work (e.g., a design engineer auditing the design control process).
Second-Party Audits (Supplier or Customer Audits)
Second-party audits are conducted by parties that have a business interest in the organization. The most common examples are customer audits of suppliers.
- Primary Objective: To evaluate the capability and performance of a current or potential supplier to meet contractual obligations, quality requirements, and delivery schedules.
- Key Characteristic: These audits are guided by customer-specific requirements, purchasing contracts, or service level agreements (SLAs). They are not independent in the purest sense, as the auditing organization has a direct commercial relationship with the auditee.
Third-Party Audits (External Certification Audits)
Third-party audits are conducted by independent, external auditing organizations, commonly known as Certification Bodies (CBs) or Registrars. These audits are governed by ISO/IEC 17021-1.
- Primary Objective: To determine if the organization's QMS conforms to all requirements of ISO 9001 and is eligible for certification.
- Key Characteristic: The certification body must be completely independent of the client organization and have no commercial interest other than the certification service. These audits follow a strict two-stage process (Stage 1 Readiness Review and Stage 2 Certification Audit) and are subject to oversight by national Accreditation Bodies (e.g., ANAB in the United States, UKAS in the United Kingdom).
| Feature | First-Party (Internal) | Second-Party (Supplier) | Third-Party (Certification) |
|---|---|---|---|
| Relationship | Self-audit (Internal) | Customer audits Supplier | Independent Registrar audits Client |
| Criteria | ISO 9001 + Internal Procedures | Contracts + Customer Requirements | ISO 9001 + Standard Rules |
| Primary Driver | Continual Improvement & Compliance | Vendor Qualification & Performance | Achieving or maintaining Certification |
| Independence | Relies on organizational cross-audits | Commercial buyer-seller relationship | Strict independent third-party status |
| Governing Standard | ISO 19011 | ISO 19011 + Contract Terms | ISO/IEC 17021-1 + ISO 19011 |
Defining the Three Pillars: Scope, Criteria, and Plan
One of the most frequent sources of confusion for certification candidates is distinguishing between the audit scope, audit criteria, and the audit plan. A lead auditor must define and apply these terms precisely.
1. Audit Scope
The audit scope defines the boundary and limits of the audit. It determines what is "in" and what is "out."
- Inclusions: Physical locations (e.g., manufacturing facility in Chicago), organizational units or departments (e.g., purchasing, production, design), specific processes (e.g., raw material receiving), product lines (e.g., medical device manufacturing line), and the time frame covered by the audit.
- Auditor Responsibility: The lead auditor must agree on the scope with the client and ensure it matches the certification boundary. For third-party audits, the scope must align with the scope statement on the ISO 9001 certificate.
2. Audit Criteria
The audit criteria represent the reference points, policies, procedures, or requirements against which the auditor compares the collected objective evidence. It is the "measuring stick."
- Inclusions: ISO 9001:2015 standard clauses, the organization’s documented procedures and policies, statutory and regulatory requirements, customer contracts, and industry-specific regulations.
- Auditor Responsibility: The auditor compares the observed reality (objective evidence) against these criteria to determine conformity or nonconformity.
3. Audit Plan
The audit plan is the operational agenda and timetable for conducting the audit. It is the schedule.
- Inclusions: Dates and times of audit activities, specific processes to be audited at specific times, names of auditors assigned to each area, names of auditees or process owners, and scheduled times for opening and closing meetings.
- Auditor Responsibility: The lead auditor drafts the audit plan and communicates it to the auditee well in advance. Unlike the scope and criteria, which are structural, the plan is practical and organizational.
Worked Example: Applying the Pillars
Consider a company, "Precision Aerospace Inc.," undergoing an audit:
- Audit Scope: The assembly facility located at 100 Aero Drive, Seattle, WA, specifically the production and quality control of aerospace fasteners.
- Audit Criteria: ISO 9001:2015 Clause 8.5 (Production and service provision), the company's Standard Operating Procedure SOP-PROD-02 (Assembly Operations), and FAA Regulation Part 21.
- Audit Plan: Day 1, 09:00 - Opening Meeting. 10:00 - Interview Production Manager. 11:00 - Observe Fastener Assembly line. 13:00 - Review calibration records. 16:00 - Daily Debrief.
Setting Objectives
Every audit must have clear objectives defined before the planning phase begins. The audit objectives address the fundamental "why" of the audit. Typical audit objectives include:
- Evaluating the QMS's conformity to the audit criteria.
- Determining the effectiveness of the QMS implementation and maintenance.
- Evaluating the QMS's capability to achieve its intended outcomes and objectives.
- Identifying potential areas for improvement in the system.
- Assessing the QMS's readiness for a certification or surveillance decision (third-party).
Without clearly defined objectives, an audit can easily drift into a subjective evaluation of personnel or focus on low-risk administrative processes, failing to add value to the organization.
An internal quality auditor is scheduled to audit the purchasing department. The auditor’s regular role is as the purchasing manager. Which audit rule or standard does this most directly violate?
During an external audit, the auditor requests the organization's documented procedure for design control and the ISO 9001:2015 standard. In this scenario, what do these documents represent?
A lead auditor defines the boundaries of an upcoming audit as "the manufacturing facility located in Austin, Texas, covering the production and packaging of dietary supplements." Under what term is this boundary officially categorized?