Before commissioning an audit, the board needs to answer three questions · who is auditing, what their relationship with the organisation is, and how the result will be used. ISO 19011 distinguishes first-, second- and third-party audits. The methodology may be similar; the authority and intended recipients of the conclusion change.


Type I · First-party auditor

Who performs it · the organisation itself or someone acting on its behalf. This may be internal staff or an external professional contracted to fulfil the internal audit function.

What they can do · review operational conformity against internal standards · detect nonconformities before they escalate · recommend improvements · serve as the system’s learning mechanism.

What it does not produce · a third-party certificate. Its report may be relevant to a regulator or a client, but it retains its internal nature and must be presented as such.

Structural limitations · audits their own peers · sees the information their position allows them to see · carries the risk of self-confirmation precisely on the issues the organisation prefers to keep quiet about.

When to use it · to assess the organisation’s own management system, investigate incidents or prepare internal decisions. If a standard requires internal auditing, the programme must address that requirement and the system’s risks.

Type II · Second-party auditor

Who they are · a professional appointed by an external interested party with a direct contractual relationship · a major client, parent company, strategic supplier or sectoral commissioning party.

What they can do · verify contractual requirements, assess performance against service agreements, examine technical capability before awarding a contract or exercise an agreed audit right.

What they cannot do · issue a certificate enforceable against parties outside the bilateral relationship. Their authority ends where the contract legitimising it ends.

The key fact of this decade · due diligence regulation requires certain large groups to identify and manage impacts in their chain of activities. Directive (EU) 2026/470 narrowed the scope and changed the timetable. The legislation does not require every review to take the form of a second-party audit; when that approach is used, the mandate and criteria must be set out in writing.

Type III · Third-party auditor

Who performs it · an auditing organisation independent of the first- or second-party relationship. When the audit forms part of an accredited certification process, it is performed by a team appointed by the certification body within its scope of accreditation.

What it produces · findings and a recommendation within the process. The certificate is issued by the certification body following a review and a decision made by people who did not participate in the audit.

What they cannot do · design or implement the solution they will later assess. They may explain the requirement and the finding; they must not take on the auditee’s management decision. Threats to impartiality are assessed and documented according to the specific relationship.

Where its strength comes from · competence, scope, impartiality and the separation between audit and decision. That chain has its own criterion in this series · Criterion 12 examines it link by link.

Third-party status is protected in every engagement. Explaining the requirement is not the same as designing the correction. The line is crossed when the auditor makes implementation decisions that they should later assess. The verbs help make it visible · the auditor asks and concludes; the organisation decides and executes.

A third-party audit can feed into certification; the decision belongs to the body, not the individual auditor.

The tool and the signature

A monitoring platform, an agent that reads logs or a copilot that prepares drafts does not constitute a party. They are tools. Their output acquires meaning within the mandate, criteria and review of the signatory. The dashboard observes; responsibility remains with the party using it.

The auditor wearing multiple hats

The risk to impartiality arises when a professional alternates between engagements of different kinds without reviewing incompatibilities. They may act as an outsourced internal auditor, as an auditor for a client and, in another context, as a certification auditor. Each role may be legitimate; the combination requires an assessment of prior relationships, information obtained and self-review threats.

Each role may be legitimate. A change of role requires an assessment of prior relationships, self-interest, familiarity and other threats to impartiality. The response depends on the engagement and the applicable scheme: it may require disclosure, independent review, a time restriction or refusal of the work. No safeguard works on its own for every case.

The criterion test

Four questions, each with an expected answer, before accepting any audit report.

Question one · who commissioned the audit and for whom will the result be issued? Expected answer · it is recorded in the engagement document. The organisation itself · first party. A client or another interested party · second. An independent auditing organisation · third; if accredited certification is also involved, the body and its scope must be identified.

Question two · how will the result be used? Expected answer · the first party informs internal decisions; the second addresses a contractual or interested-party relationship; the third provides independence. Only a certification process issues a certificate, through the chain detailed in Criterion 12.

Question three · what previous roles has this professional held with our organisation? Expected answer · a signed declaration of independence available for consultation, with roles and dates. An answer from memory, without a document, is the relationship’s first finding.

Question four · what automated tools fed into the report and who signs off on their outputs? Expected answer · platforms listed as the team’s instruments, with an identifiable human signatory for each finding. Criterion 06 explains why that signature must exist.

The system is designed to manage operations · the audit comes later, to verify what is already breathing. A board that understands the three types buys exactly the statement it needs, and knows before the incident how far each signature extends.