Find it before the auditor does.
Independent audits against ISO 9001, ISO 14001, ISO 45001 and ADOSH-SF v4.0: conducted by a certified ISO Lead Auditor who reports what is actually there, not what is comfortable to hear.
Why outsource your internal audit
Clause 9.2 of every ISO management system standard requires internal audits at planned intervals, conducted objectively and impartially. That last word is where most in-house programmes quietly fail: auditors cannot audit their own work, and in a small company almost everyone's work touches everything.
The other failure is softer and more damaging. Internal auditors who report to the person whose department they are auditing find fewer problems. A clean internal audit report followed by a certification audit full of non-conformities is one of the most common patterns we are called in to fix.
Genuine independence
We have no internal reporting line, no department to protect and no annual appraisal at stake. The report says what we found.
Certified competence
Audits led by a certified ISO Lead Auditor and Chartered Quality Professional: the same competence level as the certification body auditor who will follow.
No internal cost
No training your staff to auditor level, no pulling them off billable work for a week each year.
Auditor's eye view
We know what certification bodies sample, where they dig, and which weak answers trigger a deeper look.
Types of audit we run
| Audit type | Purpose | Typical duration |
|---|---|---|
| Internal (first party) | Satisfy clause 9.2 and find issues before certification or surveillance | 2–4 days |
| Pre-certification readiness | Simulate the Stage 2 audit so nothing is a surprise on the day | 2–3 days |
| Supplier (second party) | Assess a supplier or subcontractor's system on your behalf | 1–2 days per supplier |
| Gap analysis | Establish current status before a certification project begins | 1–2 days |
| ADOSH-SF compliance audit | Verify regulatory compliance the way an inspector would | 2–3 days |
| Post-incident system audit | Determine whether the system, not just the person, allowed the incident | 2–4 days |
How we audit
We audit to ISO 19011 principles: evidence-based, risk-focused and conducted with professional care.
- Plan. We agree scope, criteria and schedule, and issue an audit plan in advance so the right people are available. No ambush audits.
- Opening meeting. Brief, businesslike, confirming scope and logistics.
- Evidence gathering. Document review, process observation and interviews at every level, including the workforce, not just managers. Site work is done on site.
- Trace testing. We follow real cases end to end: an order through delivery, a permit through close-out, an incident through corrective action. Sampling folders proves nothing.
- Findings classification. Major and minor non-conformities, plus observations and opportunities for improvement, each with the objective evidence and the clause cited.
- Closing meeting. Findings presented and discussed before we leave. Nothing in the report is a surprise.
- Report. Issued within five working days, written to be read by management rather than only by auditors.
- Corrective action support. We review your root cause analysis and verify closure: optional, but this is where audits create value.
What you receive
The findings we raise most often
- Management review missing mandatory inputs. Clause 9.3 lists them explicitly. Minutes that omit several are a straightforward non-conformity.
- Corrective actions that treat symptoms. Root cause recorded as “human error” with retraining as the action, and the same issue recurring three months later.
- Objectives without measurement. Targets set at the start of the year and never tracked.
- Competence assumed rather than evidenced. Attendance sheets filed as proof of competence, with no assessment of whether anything was learned.
- Uncontrolled documents in use. Superseded forms circulating on site while the current version sits on the server.
- Supplier evaluation performed once. Approved supplier lists with no re-evaluation since the system was built.
- Previous audit findings not closed. Open items rolled forward from the last cycle, which certification bodies treat as a systemic failure, not a single lapse.
We publish a deeper analysis of the safety-specific version of this list in the seven findings that fail ISO 45001 audits most often.
Questions clients ask first
Yes. The standards require internal audits to be conducted objectively and impartially; they do not require the auditor to be an employee. Outsourcing is explicitly acceptable and, for small organisations, is usually the only way to achieve genuine independence.
For internal audit purposes, yes, and it is common practice, because we know the system and can go deeper faster. We are transparent about it in the audit report. Note that this is different from certification: a certification body cannot audit a system its own organisation implemented, which is why we never act as one.
The standard says at planned intervals, based on the importance and risk of the processes and the results of previous audits. In practice, every process should be audited at least once a year, with higher-risk or previously problematic areas audited more often. Most clients run one full cycle annually, timed a couple of months before their surveillance audit.
Often that is the better long-term answer, and we offer internal auditor training for exactly that reason. A common arrangement is that we run the first cycle while training your nominated auditors alongside us, then hand over and return annually for an independent check.

Let’s make your next audit a non-event.
Book a free 30-minute consultation. We will tell you honestly whether you need a consultant, and if you do, exactly what it will take.