Internal, Supplier & Pre-Certification Audits

Find it before the auditor does.

Independent audits against ISO 9001, ISO 14001, ISO 45001 and ADOSH-SF v4.0: conducted by a certified ISO Lead Auditor who reports what is actually there, not what is comfortable to hear.

Lead AuditorFormally certified
IndependentNo conflict of interest
2–5 daysTypical audit duration
Zero NCsAchieved on recertification

Why outsource your internal audit

Clause 9.2 of every ISO management system standard requires internal audits at planned intervals, conducted objectively and impartially. That last word is where most in-house programmes quietly fail: auditors cannot audit their own work, and in a small company almost everyone's work touches everything.

The other failure is softer and more damaging. Internal auditors who report to the person whose department they are auditing find fewer problems. A clean internal audit report followed by a certification audit full of non-conformities is one of the most common patterns we are called in to fix.

Genuine independence

We have no internal reporting line, no department to protect and no annual appraisal at stake. The report says what we found.

Certified competence

Audits led by a certified ISO Lead Auditor and Chartered Quality Professional: the same competence level as the certification body auditor who will follow.

No internal cost

No training your staff to auditor level, no pulling them off billable work for a week each year.

Auditor's eye view

We know what certification bodies sample, where they dig, and which weak answers trigger a deeper look.

Types of audit we run

Audit typePurposeTypical duration
Internal (first party)Satisfy clause 9.2 and find issues before certification or surveillance2–4 days
Pre-certification readinessSimulate the Stage 2 audit so nothing is a surprise on the day2–3 days
Supplier (second party)Assess a supplier or subcontractor's system on your behalf1–2 days per supplier
Gap analysisEstablish current status before a certification project begins1–2 days
ADOSH-SF compliance auditVerify regulatory compliance the way an inspector would2–3 days
Post-incident system auditDetermine whether the system, not just the person, allowed the incident2–4 days

How we audit

We audit to ISO 19011 principles: evidence-based, risk-focused and conducted with professional care.

  1. Plan. We agree scope, criteria and schedule, and issue an audit plan in advance so the right people are available. No ambush audits.
  2. Opening meeting. Brief, businesslike, confirming scope and logistics.
  3. Evidence gathering. Document review, process observation and interviews at every level, including the workforce, not just managers. Site work is done on site.
  4. Trace testing. We follow real cases end to end: an order through delivery, a permit through close-out, an incident through corrective action. Sampling folders proves nothing.
  5. Findings classification. Major and minor non-conformities, plus observations and opportunities for improvement, each with the objective evidence and the clause cited.
  6. Closing meeting. Findings presented and discussed before we leave. Nothing in the report is a surprise.
  7. Report. Issued within five working days, written to be read by management rather than only by auditors.
  8. Corrective action support. We review your root cause analysis and verify closure: optional, but this is where audits create value.

What you receive

Audit plan and schedule issued in advance
Completed audit checklists with evidence recorded against each criterion
Formal audit report with findings classified and clauses cited
Non-conformity records ready for your corrective action process
Executive summary written for management, not auditors
Prioritised action list ranked by certification risk
Evidence pack satisfying clause 9.2 for your certification body
Closure verification once corrective actions are complete

The findings we raise most often

  • Management review missing mandatory inputs. Clause 9.3 lists them explicitly. Minutes that omit several are a straightforward non-conformity.
  • Corrective actions that treat symptoms. Root cause recorded as “human error” with retraining as the action, and the same issue recurring three months later.
  • Objectives without measurement. Targets set at the start of the year and never tracked.
  • Competence assumed rather than evidenced. Attendance sheets filed as proof of competence, with no assessment of whether anything was learned.
  • Uncontrolled documents in use. Superseded forms circulating on site while the current version sits on the server.
  • Supplier evaluation performed once. Approved supplier lists with no re-evaluation since the system was built.
  • Previous audit findings not closed. Open items rolled forward from the last cycle, which certification bodies treat as a systemic failure, not a single lapse.

We publish a deeper analysis of the safety-specific version of this list in the seven findings that fail ISO 45001 audits most often.

Questions clients ask first

Yes. The standards require internal audits to be conducted objectively and impartially; they do not require the auditor to be an employee. Outsourcing is explicitly acceptable and, for small organisations, is usually the only way to achieve genuine independence.

For internal audit purposes, yes, and it is common practice, because we know the system and can go deeper faster. We are transparent about it in the audit report. Note that this is different from certification: a certification body cannot audit a system its own organisation implemented, which is why we never act as one.

The standard says at planned intervals, based on the importance and risk of the processes and the results of previous audits. In practice, every process should be audited at least once a year, with higher-risk or previously problematic areas audited more often. Most clients run one full cycle annually, timed a couple of months before their surveillance audit.

Often that is the better long-term answer, and we offer internal auditor training for exactly that reason. A common arrangement is that we run the first cycle while training your nominated auditors alongside us, then hand over and return annually for an independent check.

Let’s make your next audit a non-event.

Book a free 30-minute consultation. We will tell you honestly whether you need a consultant, and if you do, exactly what it will take.

Book a free consultation WhatsApp us