First-, Second- and Third-Party Audits
In ISO/IEC 27001 Lead Auditor training, audits are classified by who performs them and for what purpose, following ISO 19011 (guidelines for auditing management systems) and ISO/IEC 17021-1. First-party audits are internal audits conducted by, or on behalf of, the organization itself. ISO/IEC 27001… In ISO/IEC 27001 Lead Auditor training, audits are classified by who performs them and for what purpose, following ISO 19011 (guidelines for auditing management systems) and ISO/IEC 17021-1. First-party audits are internal audits conducted by, or on behalf of, the organization itself. ISO/IEC 27001 Clause 9.2 requires them at planned intervals. They verify that the Information Security Management System (ISMS) conforms to the organization's own requirements and to the standard, and that it is effectively implemented and maintained. Results feed management review (Clause 9.3) and continual improvement (Clause 10). Internal auditors may be employees or contracted consultants, but they must be objective and impartial, which means they should not audit their own work. First-party audits can also support a self-declaration of conformity. Second-party audits are performed by parties with an interest in the organization, typically customers, or by others acting on their behalf. A common example is a company auditing a cloud provider or outsourcing partner to confirm that contractual information security requirements are met. These audits relate to supplier relationship controls in ISO/IEC 27001 Annex A (5.19 to 5.22). The auditor is external to the auditee but not fully independent, because the auditing party has a commercial interest in the outcome. Third-party audits are conducted by independent external organizations, such as accredited certification bodies or regulators. Certification bodies operate under ISO/IEC 17021-1 and ISO/IEC 27006, which set competence and impartiality requirements for ISMS certification. The process includes a Stage 1 audit, which reviews documentation and readiness. It is followed by a Stage 2 audit, which evaluates implementation and effectiveness. If the outcome is successful, a certificate valid for three years is issued, with annual surveillance audits and a recertification audit before expiry. Third-party audits offer the highest level of independence and public assurance. Understanding these distinctions helps a Lead Auditor apply the principles of independence, evidence-based approach and fair presentation appropriately in each audit context.
First-, Second- and Third-Party Audits: A Complete Guide for ISO 27001 Lead Auditors
Introduction
Every audit an ISO/IEC 27001 Lead Auditor carries out belongs to one of three categories: first-party, second-party or third-party. These categories come from ISO 19011:2018 (Guidelines for auditing management systems). They are also reflected in ISO/IEC 17021-1 and ISO/IEC 27006 for certification bodies. Knowing the differences is a foundation of audit competence and comes up often in lead auditor exams.
Why It Is Important
Classifying audits by party is not just labelling. The type of audit decides:
• Who commissions the audit and who receives the results.
• The level of independence expected of the auditor.
• The purpose and outcome: internal improvement, supplier assurance or formal certification.
• The governing rules: organisational procedures, contracts, or accreditation standards such as ISO/IEC 17021-1 and ISO/IEC 27006.
• The consequences of findings: corrective actions, contract decisions, or the granting, suspension or withdrawal of certification.
For an ISMS, all three types work together:
• Internal audits are mandatory under Clause 9.2 of ISO/IEC 27001.
• Supplier audits support Annex A controls on supplier relationships (A.5.19 to A.5.23 in the 2022 edition).
• Certification audits give external, impartial assurance to customers, regulators and other interested parties.
What They Are
1. First-Party Audits (Internal Audits)
• Conducted by, or on behalf of, the organisation itself, for management review and other internal purposes.
• May be done by the organisation's own staff or by an external consultant hired by the organisation. It is still first-party because the organisation is auditing itself for its own purposes.
• May form the basis of an organisation's self-declaration of conformity.
• Required by ISO/IEC 27001 Clause 9.2. The organisation must plan an audit programme, define criteria and scope, choose objective and impartial auditors, report results to relevant management and keep documented information as evidence.
• Independence can be shown by the auditor being free from responsibility for the activity being audited, even in small organisations.
• Purpose: check conformity with the organisation's own requirements and the standard, confirm the ISMS is effectively implemented and maintained, and find opportunities for improvement.
2. Second-Party Audits (External Audits by Interested Parties)
• Conducted by parties that have an interest in the organisation, such as customers, or by others on their behalf.
• The most common example is a customer auditing its supplier, for instance a bank auditing a cloud service provider.
• Usually based on a contract, agreement or purchasing relationship. Criteria often include contractual security requirements, service level agreements, data processing agreements and relevant standards.
• Results support decisions such as supplier selection, contract renewal, risk acceptance or requests for improvement.
• They do not lead to accredited certification.
• Other examples: a parent company auditing a subsidiary under a separate commercial arrangement, or a consultant engaged by a customer to audit that customer's supplier.
3. Third-Party Audits (Independent External Audits)
• Conducted by independent auditing organisations with no conflict of interest.
• Examples:
- Certification bodies granting ISO/IEC 27001 certification.
- Regulatory or statutory audits by government agencies.
• Accredited certification bodies follow ISO/IEC 17021-1 and, for ISMS, ISO/IEC 27006.
• Typical cycle:
- Initial certification audit: Stage 1 (documentation and readiness review) and Stage 2 (evaluation of implementation and effectiveness).
- Surveillance audits: at least annually.
- Recertification audit: before the three-year certificate expires.
• Outcome: a certificate recognised by interested parties, with the highest level of independence and impartiality.
Summary Comparison
• First-party: organisation audits itself. Purpose: internal assurance and improvement. Independence: auditors are not responsible for the area audited. Output: internal report, input to management review.
• Second-party: interested party audits the organisation. Purpose: supplier or partner assurance. Independence: auditor is external, but the commissioning party has a commercial interest. Output: report to the customer or interested party.
• Third-party: independent body audits the organisation. Purpose: certification or regulatory compliance. Independence: highest, with no commercial interest in the result. Output: certification decision or regulatory finding.
How It Works in Practice
The Audit Process Is Largely the Same
All three types generally follow the ISO 19011 process:
• Initiating the audit
• Preparing audit activities
• Conducting audit activities: opening meeting, collecting and verifying evidence, generating findings, closing meeting
• Preparing and distributing the report
• Completing the audit
• Conducting audit follow-up
The principles of auditing apply to all of them: integrity, fair presentation, due professional care, confidentiality, independence, and an evidence-based and risk-based approach.
What Changes Between the Types
• Client:
- First-party: top management or the ISMS owner.
- Second-party: the customer.
- Third-party: the auditee requests certification, but the certification body controls the process.
• Criteria:
- First-party: internal policies plus ISO/IEC 27001.
- Second-party: contracts plus the standard.
- Third-party: ISO/IEC 27001 requirements plus the organisation's own ISMS documentation.
• Rules on auditor competence and impartiality: these become stricter as you move from first- to third-party.
• Consequences: internal corrective action, commercial decisions, or certification decisions.
Worked Scenario
A software company, SecureSoft, runs an ISMS.
• Its internal audit team audits the HR department's onboarding controls. This is first-party.
• Its biggest client, a hospital group, sends auditors to check how SecureSoft protects patient data under their contract. This is second-party.
• An accredited certification body performs SecureSoft's surveillance audit. This is third-party.
• SecureSoft hires a consultancy to perform its internal audit. This is still first-party, because it is done on behalf of SecureSoft for its own purposes.
• SecureSoft audits its own data centre provider. This is second-party, from SecureSoft's perspective as the customer.
Related Concepts Often Tested
• Combined audit: auditing two or more management systems together, for example ISO/IEC 27001 and ISO 9001.
• Joint audit: two or more auditing organisations auditing a single auditee.
• Audit programme: arrangements for one or more audits planned for a specific time frame, managed by the audit programme manager.
• Self-declaration: a first-party claim of conformity, which is not the same as certification.
• Consultancy conflict: under ISO/IEC 17021-1, a certification body must not provide ISMS consultancy to the clients it certifies. This is a key threat to third-party impartiality.
Exam Tips: Answering Questions on First-, Second- and Third-Party Audits
1. Identify who commissioned the audit and for whose benefit.
This is the most reliable test. Ask: Who is the audit client, and what is their relationship to the auditee?
• Self equals first-party.
• Customer or interested party equals second-party.
• Independent body equals third-party.
2. Do not be misled by who physically performs the audit.
An external consultant performing an internal audit for the organisation is still first-party. A consultant hired by a customer to audit a supplier is second-party. Exam writers often use this trap.
3. Link certification only to third-party audits.
If the question mentions certificates, accreditation, Stage 1 and Stage 2, surveillance or recertification, the answer is almost always third-party.
4. Link Clause 9.2 to first-party audits.
When a question refers to ISO/IEC 27001 internal audit requirements, management review input or the audit programme required by the standard, think first-party.
5. Link contracts and suppliers to second-party audits.
Keywords such as supplier, vendor, outsourcing, contract, SLA, customer requirement or right-to-audit clause point to second-party.
6. Remember the independence scale.
Independence generally increases from first- to second- to third-party. Even first-party auditors must be objective and impartial and must not audit their own work. Scenario questions often present an internal auditor checking a process they designed. The correct answer flags this as a threat to impartiality.
7. Watch for perspective shifts.
The same audit can be described from different viewpoints. When Company A audits Supplier B, it is second-party. The classification depends on the relationship, not on which side you are reading about.
8. Know the governing standards.
• ISO 19011: guidance for all audit types.
• ISO/IEC 17021-1: requirements for certification bodies (third-party).
• ISO/IEC 27006: ISMS-specific requirements for certification bodies.
• ISO/IEC 27007: guidance specific to ISMS auditing.
9. For essay or scenario answers, use a structured approach.
• Define the audit type using ISO 19011 language.
• Identify the client, auditee and auditor relationship.
• State the purpose and criteria.
• Comment on independence and impartiality.
• Explain the expected outcomes and follow-up.
This shows reasoning, not just memorisation, which examiners reward.
10. Eliminate absolute statements.
Be cautious with options using words like always or never. For example, the statement "first-party audits are never performed by external people" is false.
11. Remember regulators.
Audits by regulators or government agencies are generally classed as third-party, because they are independent of the auditee and have no commercial interest.
Quick Memory Aid
• 1st = Me auditing myself.
• 2nd = You (my customer) auditing me.
• 3rd = Them (an independent body) auditing me.
Conclusion
First-, second- and third-party audits share the same principles and process, but differ in client, purpose, independence and consequences. A Lead Auditor must classify audits correctly, understand the rules that apply to each, and apply that knowledge to realistic scenarios. In the exam, focus on the relationship between the audit client and the auditee, watch for wording traps about who performs the audit, and link each type to its typical keywords and governing standards.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!