First-, Second- and Third-Party Audit Programs
In ISO/IEC 27001 auditing, audit programs are classified by the relationship between the auditor and the auditee. Guidance for managing all three types comes from ISO 19011 and ISO/IEC 27007. These standards describe how to set program objectives, assess program risks and opportunities, assign reso… In ISO/IEC 27001 auditing, audit programs are classified by the relationship between the auditor and the auditee. Guidance for managing all three types comes from ISO 19011 and ISO/IEC 27007. These standards describe how to set program objectives, assess program risks and opportunities, assign resources, implement audits, and monitor, review and improve the program. First-party audits are internal audits conducted by, or on behalf of, the organization itself. Clause 9.2 of ISO/IEC 27001 requires the organization to plan, establish, implement and maintain an audit program that defines frequency, methods, responsibilities, planning requirements and reporting. Audits must occur at planned intervals. They determine whether the ISMS conforms to the organization's own requirements and to the standard, and whether it is effectively implemented and maintained. Auditors must be objective and impartial, which typically means they do not audit their own work. Results feed into management review and corrective action. Second-party audits are performed by parties with an interest in the organization, most commonly customers auditing their suppliers, or by others acting on their behalf. They verify that contractual, regulatory or information security requirements are being met. They support the supplier relationship controls in Annex A, such as controls 5.19 to 5.22 in the 2022 edition. The program is driven by supplier risk, the criticality of outsourced services and contract terms. Results may influence supplier selection, retention or improvement plans. Third-party audits are conducted by independent external organizations, typically accredited certification bodies, to grant certification. They follow ISO/IEC 17021-1 and ISO/IEC 27006-1, which define auditor competence, impartiality and audit duration. The certification cycle includes a Stage 1 audit that reviews documentation and readiness, and a Stage 2 audit that evaluates implementation and effectiveness. Certification is then maintained through annual surveillance audits and a recertification audit every three years. For a Lead Auditor, understanding these distinctions clarifies audit objectives, independence expectations, audit criteria, reporting obligations and how findings will be used. This ensures each program adds value while remaining credible to stakeholders.
First-, Second- and Third-Party Audit Programs: A Complete Guide for the ISO/IEC 27001 Lead Auditor
Introduction
Every ISO/IEC 27001 Lead Auditor must understand who is auditing whom, why, and on whose authority. Audits are classified into three types: first-party, second-party and third-party. Each has a different purpose, a different client, different independence requirements and different governing standards. Managing an audit programme well depends on getting this classification right, and exam questions test it constantly.
Why This Topic Is Important
1. Credibility and trust: The type of audit decides how much confidence outsiders can place in the results. A certificate from an accredited certification body (third party) carries more market weight than an internal report (first party).
2. Compliance with ISO/IEC 27001: Clause 9.2 requires organisations to run internal audits at planned intervals. This is a first-party audit programme, and an ISMS cannot be certified without it.
3. Supply chain security: Clause 8.1 and Annex A controls 5.19 to 5.22 (supplier relationships, supplier agreements, ICT supply chain, and monitoring of supplier services) often lead organisations to audit their suppliers. These are second-party audits.
4. Certification and accreditation: Third-party audits are run under ISO/IEC 17021-1 and ISO/IEC 27006-1. They lead to certification that customers, regulators and partners recognise.
5. Programme design: ISO 19011:2018 Clause 5 explains how to manage an audit programme. The programme's objectives, risks, resources and competence needs differ by audit type.
6. Professional conduct: Independence, impartiality and conflict-of-interest rules vary by audit type. Lead auditors must apply them correctly to stay ethical.
What It Is: Definitions
First-Party Audit (Internal Audit)
An audit carried out by, or on behalf of, the organisation itself.
- Purposes: management review, internal improvement, and showing conformity (for example, before certification).
- Performed by internal staff or by external consultants hired by the organisation.
- Required by ISO/IEC 27001 Clause 9.2.
- Independence is shown by auditors not auditing their own work, rather than by being external.
- The client and the auditee are the same organisation.
Second-Party Audit (External Audit by an Interested Party)
An audit carried out by a party with an interest in the organisation, usually a customer, or by someone acting for them.
- Examples: a bank auditing its cloud provider; a government agency auditing a contractor; a parent company auditing a subsidiary under contract.
- Purposes: check that a supplier meets contractual, regulatory or security requirements, and support supplier selection and monitoring.
- The audit criteria may include ISO/IEC 27001, contract clauses, service-level agreements or the customer's own security requirements.
- The client is the customer and the auditee is the supplier.
Third-Party Audit (Independent External Audit)
An audit carried out by an independent auditing organisation with no stake in the outcome.
- Examples: certification bodies such as BSI, DNV, TÜV or SGS performing ISO/IEC 27001 certification audits; regulators performing statutory audits.
- Purposes: certification, registration, regulatory compliance and recognition.
- Governed by ISO/IEC 17021-1 (requirements for certification bodies) and ISO/IEC 27006-1 (extra requirements for ISMS certification bodies).
- Certification bodies are usually accredited by a national accreditation body, such as UKAS, ANAB or DAkkS.
Note on ISO 19011:2018
ISO 19011 Clause 3 groups audit types as:
- Internal audits (first party)
- External audits, which include second-party and third-party audits
How It Works
1. First-Party Audit Programme Lifecycle
- Top management sets the programme objectives, linked to ISMS objectives and risks.
- An audit programme manager is appointed and given resources.
- Scope, frequency and methods are set according to the importance of the processes and the results of previous audits (ISO/IEC 27001 Clause 9.2.2).
- Auditors are chosen to ensure objectivity and impartiality, so they do not audit their own work.
- Audits are conducted and results are reported to relevant management.
- Nonconformities feed into corrective action (Clause 10.2) and management review (Clause 9.3).
- Documented information is kept as evidence of the programme and its results.
2. Second-Party Audit Programme Lifecycle
- Starts with supplier risk assessment, so that critical suppliers handling sensitive data get priority.
- The right to audit is set in contracts or supplier agreements (Annex A 5.20).
- Criteria are defined, for example ISO/IEC 27001 clauses, contractual security requirements or legal obligations.
- Audits may be on-site, remote or questionnaire-based, depending on risk.
- Findings lead to supplier corrective action plans and may affect contract renewal.
- Results feed into supplier performance monitoring (Annex A 5.22).
3. Third-Party Certification Audit Programme
Third-party certification follows a three-year cycle:
- Initial certification audit:
- Stage 1: review documentation and readiness. Covers scope, ISMS design, the Statement of Applicability, risk assessment, and internal audit and management review evidence.
- Stage 2: evaluate implementation and effectiveness of the ISMS on site.
- Surveillance audits: usually annual, in years one and two.
- Recertification audit: before the certificate expires in year three.
- Special audits: short-notice audits, audits for scope extensions, or follow-up of major nonconformities.
- Certification decisions are made by people who did not conduct the audit, which keeps the process impartial.
- Audit duration is calculated using ISO/IEC 27006-1 tables based on the number of personnel and complexity.
Key Comparison
Who initiates:
- First party: the organisation itself.
- Second party: the customer or other interested party.
- Third party: the organisation, by applying for certification, but the audit is performed by an independent body.
Primary purpose:
- First party: internal assurance and improvement.
- Second party: supplier assurance and contract compliance.
- Third party: certification and independent recognition.
Independence level:
- First party: lowest (organisational objectivity).
- Second party: medium (external, but with a commercial interest).
- Third party: highest (no interest in the outcome).
Governing guidance:
- First party: ISO/IEC 27001 Clause 9.2 and ISO 19011.
- Second party: ISO 19011 and contract terms.
- Third party: ISO/IEC 17021-1, ISO/IEC 27006-1 and ISO 19011 principles.
Output:
- First party: internal audit report and corrective actions.
- Second party: supplier audit report, which may affect the contract.
- Third party: certificate granted, maintained, suspended or withdrawn.
Principles Common to All Three (ISO 19011 Clause 4)
- Integrity
- Fair presentation
- Due professional care
- Confidentiality
- Independence
- Evidence-based approach
- Risk-based approach
Common Pitfalls and Misconceptions
- Misconception: An external consultant doing your internal audit makes it a third-party audit.
Reality: It is still a first-party audit, because it is done on behalf of the organisation.
- Misconception: Second-party audits lead to certification.
Reality: They do not. Only accredited third-party audits lead to recognised certification.
- Misconception: Certification bodies can give consultancy to the clients they certify.
Reality: They must not. ISO/IEC 17021-1 prohibits this because it threatens impartiality.
- Misconception: Internal auditors must come from outside the organisation.
Reality: They need objectivity and impartiality, which usually means not auditing their own area. They do not need to be external.
Exam Tips: Answering Questions on First-, Second- and Third-Party Audit Programs
Tip 1: Identify the relationship first. Ask: who requested the audit, who is the auditee, and who benefits? If the organisation audits itself, it is first party. If a customer audits a supplier, it is second party. If an independent body audits for certification or regulation, it is third party.
Tip 2: Watch for the phrase 'on behalf of'. An audit performed by a consultant on behalf of the organisation is still first party. An audit by a consultancy hired by a customer to audit its supplier is still second party.
Tip 3: Link to the right clause or standard.
- Internal audit: ISO/IEC 27001 Clause 9.2.
- Supplier audits: Annex A 5.19 to 5.22 and Clause 8.1 (externally provided processes).
- Certification: ISO/IEC 17021-1 and ISO/IEC 27006-1.
- Audit programme management guidance: ISO 19011 Clause 5.
Tip 4: Remember the certification cycle. Expect questions on Stage 1 versus Stage 2, surveillance frequency (at least annually), the three-year certificate validity, and what happens with major nonconformities. Certification cannot be granted until major nonconformities are corrected or an acceptable corrective action plan is verified.
Tip 5: Independence and impartiality scenarios. If a question describes a certification body auditor who previously helped implement the client's ISMS, the answer usually points to a conflict of interest. ISO/IEC 17021-1 typically requires at least two years between consultancy and auditing the same client. For internal audits, the key point is that auditors should not audit their own work.
Tip 6: Purpose drives the answer. If a scenario asks which audit type best gives market recognition, choose third party. For confidence in a specific supplier against contract terms, choose second party. For continual improvement and readiness checks, choose first party.
Tip 7: Scenario-based questions. In essay or case-study exams, structure your answer as:
1. Identify the audit type.
2. State the objectives.
3. Name the applicable criteria.
4. Describe how the programme should be managed: risks, resources, competence and records.
5. Explain the expected outputs and follow-up.
Tip 8: Know who owns the audit programme.
- First party: the organisation's audit programme manager.
- Second party: the customer's supplier management or audit function.
- Third party: the certification body, which manages the client's audit programme over the certification cycle.
Tip 9: Beware of distractor answers. Wrong options often mix up terms. For example, they may say second-party audits grant certificates, or that internal audits must be done by accredited bodies. Eliminate options that break these basic definitions.
Tip 10: Use precise vocabulary. Use terms such as audit client, auditee, audit criteria, audit scope, audit programme, audit plan, objectivity, impartiality and accreditation. Examiners reward correct terminology from ISO 19011 and ISO/IEC 17021-1.
Sample Exam Question
Question: A hospital hires an external consulting firm to check whether its own ISMS meets ISO/IEC 27001 before applying for certification. What type of audit is this?
Answer: A first-party (internal) audit, because it is performed on behalf of the hospital for its own purposes. The fact that the auditors are external does not change the audit type.
Summary
- First-party audits are internal audits for self-assessment and improvement.
- Second-party audits are customer-driven audits of suppliers.
- Third-party audits are independent, accredited audits for certification.
- A competent ISO/IEC 27001 Lead Auditor can tell them apart quickly, apply the correct standards and independence rules, and manage each programme using the risk-based approach in ISO 19011.
- In the exam, always find the relationship and purpose first. The correct answer usually follows from that.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!