<img src="https://secure.office-information-24.com/785669.png" style="display:none;">
Glossary

External Audit

Also called: Second-Party or Third-Party Audit
An external audit is an audit conducted by a party outside the organization being audited, distinguishing it from an internal, or first-party, audit performed by the organization on itself. External audits are typically categorized as second-party audits, conducted by a customer or their representative, or third-party audits, conducted by an independent certification body to verify conformance to a standard such as ISO 9001. 

Quick facts

Category Independent, outside verification of the QMS
Used by Manufacturing, medical devices, pharmaceuticals, aerospace, automotive and other regulated industries
Also called None widely standardized
Related standards ISO 9001, ISO 13485, AS9100, IATF 16949, ISO 19011
Related processes Internal audit, supplier audit, audit management, CAPA
Semantic match external audit, second-party audit, third-party audit, certification audit

What is External Audit?

An external audit is conducted by someone outside the organization being audited, in contrast to an internal audit performed by the organization's own trained personnel. External audits generally fall into two categories: second-party audits, conducted by a customer or a representative acting on the customer's behalf, and third-party audits, conducted by an independent certification body.

Second-party audits are commonly used by customers to qualify or continue approving a supplier, evaluating whether the supplier's quality system and practices meet the customer's expectations. Third-party audits are typically conducted by an accredited certification body to verify and maintain an organization's certification to a standard such as ISO 9001, ISO 13485 or AS9100.

Unlike internal audits, which an organization schedules and controls itself, external audits are initiated by an outside party according to their own schedule, whether a customer's supplier qualification cycle or a certification body's surveillance and recertification schedule.

Why is External Audit important?

External audits provide independent verification of an organization's quality system, offering a level of objectivity that internal audits, performed by the organization on itself, cannot fully replicate.

For organizations seeking or maintaining certification, third-party external audits are the mechanism through which that certification is granted and continued, making them essential to doing business in markets or with customers that require certification.

Second-party audits from customers also directly affect commercial relationships, since audit results can influence whether a supplier remains approved or qualifies for additional business.

How does External Audit work?

A typical external audit process includes:

  1. Notification. The organization is notified of the upcoming audit, its scope and schedule.
  2. Preparation. The organization reviews readiness, addressing any known gaps in advance.
  3. On-site or remote audit. The external auditor reviews records, interviews personnel and observes processes.
  4. Findings. The auditor documents conformances, nonconformances and observations.
  5. Response. The organization responds to findings, often with corrective action plans for nonconformances.
  6. Certification or approval decision. The certification body or customer determines the outcome, such as certification, continued approval, or required follow-up.

Second-Party Audit vs. Third-Party Audit

Comparison Second-Party Audit Third-Party Audit
Conducted by A customer or their representative An independent, accredited certification body
Purpose Supplier qualification and oversight Verification of certification conformance

Real-world examples of External Audit

An aerospace supplier undergoes a third-party surveillance audit from its AS9100 certification body, addressing a minor finding related to calibration records before the audit is closed.

A medical device manufacturer undergoes a second-party audit from a major customer as part of an ongoing supplier qualification review, demonstrating its quality system continues to meet the customer's expectations.

A contract manufacturer prepares for an upcoming ISO 9001 recertification audit by reviewing internal audit results and closing open CAPAs in advance, reducing the risk of surprises during the external review.

Regulations and standards related to External Audit

ISO 9001 does not use the specific terms "second-party" or "third-party" audit within its clauses, but certification to the standard itself is achieved and maintained through third-party audits conducted by an accredited certification body. ISO 19011 provides widely referenced guidance on auditing management systems generally, applicable to internal and external audits alike.

Customer-specific requirements, particularly common in automotive and aerospace supply chains, frequently include second-party audit provisions as part of supplier qualification and ongoing oversight.

Required by

How QT9 helps with External Audit

QT9 QMS external audit readiness capabilities

  • Maintain audit-ready documentation, records and evidence at all times.
  • Track and close internal audit findings and CAPAs ahead of external audits.
  • Provide instant access to calibration, training and document control records.
  • Support electronic signatures and complete audit trails for external review.
  • Give customers and certification bodies streamlined access to relevant records.
  • Reduce audit preparation time with centralized, real-time quality data.

Request an Audit Management Demo Explore Audit Prep Software →

See QT9 Software in Action

Discover how QT9 Software helps manufacturers improve efficiency, strengthen compliance and connect quality management and ERP processes within one integrated platform.

Common mistakes with External Audit

Common mistakes include treating external audit preparation as a last-minute scramble rather than maintaining continuous audit readiness through consistent internal audit and CAPA discipline.

Other problems include failing to close prior external audit findings before the next audit cycle, which can raise concerns about the organization's overall commitment to addressing identified issues.

Frequently asked questions

A second-party audit is conducted by a customer or their representative, typically for supplier qualification or oversight. A third-party audit is conducted by an independent, accredited certification body to verify conformance to a standard such as ISO 9001.
An internal audit, or first-party audit, is conducted by the organization's own trained personnel. An external audit is conducted by someone outside the organization, whether a customer or a certification body.
Third-party external audits, conducted by an accredited certification body, are the mechanism through which an organization achieves and maintains certification to standards such as ISO 9001, ISO 13485 or AS9100.
Frequency varies by type. Third-party certification audits typically follow a defined cycle, such as annual surveillance audits and periodic recertification, while second-party customer audits depend on the customer's own supplier oversight schedule.
Yes. Findings from a second-party customer audit can influence whether a supplier remains approved, qualifies for additional business, or requires corrective action before the relationship continues unchanged.
Strong preparation typically involves maintaining continuous audit readiness, such as keeping documentation current, closing internal audit findings and CAPAs promptly, and reviewing records for completeness well before the external audit occurs.

Related quality management terms

Related content

Ready to Transform Your Business?

See how QT9 Software helps manufacturers simplify operations, improve traceability and drive continuous improvement with integrated quality management and ERP software.

Last reviewed: July 21, 2026