Every quality professional knows that effective audits depend on clear communication. When auditors and auditees speak the same language, misunderstandings decrease and the entire audit process becomes more efficient. ISO 19011 provides the foundational terminology that makes this shared understanding possible, with Clause 3 specifically dedicated to establishing standardized terms and definitions for management system audits.

Table of Contents

What exactly is an audit?

At its core, an audit is a systematic, independent, and documented process for obtaining objective evidence and evaluating it objectively to determine the extent to which audit criteria are fulfilled. This definition contains three critical elements that distinguish audits from casual inspections or reviews.

Systematic means the audit follows a planned, methodical approach rather than random checking. Independent ensures the auditor maintains objectivity and has no vested interest in the outcome. Documented requires that everything-from the audit plan to findings-is recorded in a verifiable manner. These three characteristics work together to make audits reliable tools for assessing organizational performance.

Core audit terminology

Understanding the relationship between audit criteria, evidence, and findings is essential for anyone involved in quality management. These three concepts form the backbone of every audit activity.

Audit criteria

Audit criteria represent the set of policies, procedures, or requirements used as a reference against which objective evidence is compared. Think of criteria as the measuring stick for the audit. They might include external standards like ISO 22000 or FSSC 22000, regulatory requirements from bodies like the FDA or FSSAI, internal company policies, or contractual obligations with customers or suppliers. Without clearly defined criteria, an audit lacks direction and purpose.

Audit evidence

Audit evidence consists of records, statements of fact, or other information that is relevant to the audit criteria and verifiable. This evidence forms the foundation for audit conclusions. Evidence can be obtained through observation, document review, interviews, measurement, or testing. The key requirement is that evidence must be objective-meaning it can be verified independently-rather than based on opinions or assumptions.

Audit findings

Audit findings are the results of evaluating collected audit evidence against audit criteria. When auditors compare what they observed (evidence) against what should be happening (criteria), they generate findings. These findings typically fall into categories such as conformity (requirements are met), non-conformity (requirements are not met), or observations (potential improvements or risks that warrant attention but don’t constitute violations).

Audit conclusions

The audit conclusion represents the outcome of an audit after considering all audit findings and the audit objectives. While findings address specific aspects of the management system, conclusions provide an overall assessment of how well the organization meets the established criteria.

Types of audits explained

ISO 19011 distinguishes between different audit types based on who conducts them and their relationship to the organization being audited. Understanding these distinctions helps organizations plan their audit programs effectively.

First-party audits (internal audits)

First-party audits are conducted by or on behalf of the organization itself for management review and other internal purposes. An employee from one department might audit another department, or the organization might hire a consultant to perform the audit. The important distinction is that the auditor acts on behalf of the company rather than an external party.

Internal audits serve as powerful tools for continuous improvement. They allow organizations to identify problem areas, discover where processes don’t align, and find opportunities for enhancement before external auditors arrive. All ISO management system standards require organizations to perform internal audits as a fundamental element of their management system.

Second-party audits (external supplier audits)

Second-party audits occur when parties having an interest in the organization, such as customers, audit their suppliers to ensure contractual requirements are met. A food manufacturer might audit an ingredient supplier to verify they follow agreed-upon food safety practices, or a retailer might audit a contract manufacturer to confirm quality specifications are maintained.

These audits focus on elements specific to the business relationship between customer and supplier. Even if a supplier holds ISO certification, customers may still conduct second-party audits to examine contract-specific requirements that fall outside standard certification scope.

Third-party audits (certification audits)

Third-party audits are performed by independent auditing organizations such as certification bodies or governmental agencies. These auditors have no business relationship with the organization beyond the audit itself, which provides maximum objectivity.

The most common third-party audit involves certification bodies verifying that an organization’s management system conforms to standards like ISO 9001 or ISO 14001. Successful third-party audits result in certification that demonstrates to stakeholders that the organization meets internationally recognized requirements.

Combined audits

A combined audit occurs when two or more management systems are audited together at a single organization. For example, an auditor might simultaneously assess an organization’s quality management system (ISO 9001) and environmental management system (ISO 14001). When these multiple systems are fully integrated, the organization maintains what’s called an integrated management system.

Joint audits

Joint audits happen when two or more auditing organizations cooperate to audit a single organization. This might occur when multiple certification bodies or regulatory agencies need to assess the same facility and agree to conduct their audits together for efficiency.

Key roles in the audit process

Clear role definitions prevent confusion about responsibilities and authority during audits. ISO 19011 defines several key participants in the audit process.

Auditor

An auditor is a person with the demonstrated competence to conduct an audit. This competence includes technical knowledge relevant to the audit scope, understanding of audit techniques, and appropriate personal attributes like ethical behaviour, open-mindedness, and professionalism. Auditors must perform their work ethically, with honesty and responsibility, and should only undertake audit activities if competent to do so.

Audit team

An audit team consists of one or more auditors conducting an audit, supported when needed by technical experts. One auditor is appointed as the audit team leader, who carries responsibility for managing the audit process and ensuring objectives are met. The team composition depends on the audit scope and complexity-a simple process audit might require a single auditor, while a comprehensive system audit might need multiple auditors with various specializations.

Auditee

The auditee is the organization or parts thereof being audited. This includes the management, staff, and processes subject to examination during the audit. Auditees have responsibilities too-they must provide access to relevant information, facilities, and personnel to enable the audit to proceed effectively.

Audit client

The audit client is the organization or person requesting an audit. For internal audits, the audit client is typically management or a specific department within the organization. For external audits, the client might be a customer conducting supplier audits or an organization seeking certification. The audit client defines the audit scope and criteria, receives the audit report, and determines how findings will be addressed.

Additional essential terms

Beyond the core concepts, several other terms appear frequently in audit contexts.

Audit programme refers to the arrangements for a set of one or more audits planned for a specific time frame and directed toward a specific purpose. Organizations typically develop annual audit programmes that schedule internal audits throughout the year, considering factors like previous findings, process changes, and regulatory requirements.

Audit scope describes the extent and boundaries of an audit, including physical locations, organizational units, activities, and processes to be examined, as well as the time period covered.

Audit plan provides the detailed description of activities and arrangements for a specific audit, including objectives, criteria, team assignments, and schedule.

Why standardized terminology matters

Using consistent audit terminology delivers practical benefits across the organization. When everyone understands what auditors mean by terms like “non-conformity” or “objective evidence,” audit reports become clearer and corrective actions more focused. Standardized language also enables auditors working independently to reach similar conclusions in similar circumstances, making the entire audit process more reliable and reproducible.

For food safety professionals and quality managers, familiarity with these definitions helps in preparing for audits, interpreting findings correctly, and communicating effectively with certification bodies and customers.

What do you think? How has standardized audit terminology improved communication in your organization’s quality management activities? Have you experienced situations where unclear terminology led to misunderstandings during audits?

How useful was this post?

Click on a star to rate it!

Average rating 5 / 5. Vote count: 1

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

References
  1. https://www.dnv.com/assurance/articles/what-is-an-iso-audit/
  2. https://committee.iso.org/files/live/sites/tc176sc2/files/documents/ISO%209001%20Auditing%20Practices%20Group%20docs/Auditing%20General/APG-EvidenceCollection2015.pdf
  3. https://emsmastery.com/2020/12/08/what-are-first-party-second-party-third-party-audits/
  4. https://www.certaintysoftware.com/whats-a-first-second-and-third-party-audit/
  5. https://en.wikipedia.org/wiki/ISO_19011
  6. https://asq.org/quality-resources/iso-19011
  7. https://antarisconsulting.com/iso-19011-update/

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Food Safety and Quality Management Systems

1 Introduction to Management systems

  1. Introduction to ISO 9001
  2. ISO 9000
  3. Introduction to ISO 14001:2004
  4. How to Use ISO 14001
  5. Introduction to OHSAS 18001:2007
  6. How to Use OHSAS 18001:2007
  7. Introduction to ISO/IEC 27001
  8. The PDCA Model

2 Auditing

  1. Clause 1 – Scope of the Standard
  2. Clause 2 – Normative References
  3. Clause 3 – Terms and Definitions
  4. Clause 4 – Principles of Auditing
  5. Clause 5 – Managing an Audit Program
  6. Clause 6 – Audit Activities
  7. Clause 7 – Competence and Evaluation of Auditors

3 Standardization and Accreditation

  1. International Accreditation Forum (IAF)
  2. International Laboratory Accreditation Cooperation (ILAC)
  3. Quality Council of India (QCI)
  4. National Accreditation Board for Testing and Calibration Laboratories (NABL)
  5. ISO/TS 22003:2007 Food Safety Management System
  6. ISO Guide 65: General Requirements for Bodies Operating Product Certification Systems
  7. ISO/IEC 17020:1998 General Criteria for the Operation of Various Types of Bodies Performing Inspections
  8. ISO/IEC 17021:2006 – Conformity Assessment-Requirements for Bodies Providing Audit and Certification of Management Systems
  9. ISO 17025:2005 General Requirements for the Competence of Testing and Calibration Laboratories

4 ISO 9001-2000 – An Overview

  1. ISO 9000
  2. Quality Management Principles
  3. ISO 9000:2005, Quality Management Systems: Fundamentals and Vocabulary
  4. ISO 9001:2000, Quality Management Systems: Requirements
  5. Steps for Implementing Quality Management Systems
  6. Benefits of ISO 9001:2000
  7. ISO 9004:2000, Quality Management Systems: Guidelines for Performance Improvements
  8. Relationship with ISO 9001:2000
  9. Self-assessment Model

5 ISO 9001-2000 – Structure

  1. Documentation Structure of ISO 9001:2000
  2. Quality Manual
  3. Mandatory Procedures
  4. Standard Operating Procedures (SOPs)
  5. Process Definition Documents
  6. Work Instructions
  7. Miscellaneous Documents
  8. Formats and Records
  9. ISO 9001:2000 Clauses

6 Clause wise interpretation of ISO 9001-2000

  1. Clause 1: Scope
  2. Clause 2: Normative Reference
  3. Clause 3: Terms and Definitions
  4. Clause 4: Quality Management System
  5. Clause 5: Management Responsibility
  6. Clause 6: Resource Management
  7. Clause 7: Product Realization
  8. Clause 8: Measurement, Analysis and Improvement

7 ISO 9001-2000 – Case Studies

  1. Engineering Job Work Organisation
  2. Software Development Organisation
  3. Management Review in Engineering
  4. Customer-Related Processes in Software
  5. Internal Audits in Engineering
  6. Design and Development in Software
  7. Corrective and Preventive Actions in Software
  8. Customer Property Management in Engineering

8 ISO 22000-2005 – An Overview

  1. What Does ISO 22000 Bring to the HACCP Method?
  2. System Components
  3. Communication between Participants in the Food Industry
  4. ISO 22000: A Passport for Exporting?
  5. Why do Companies Commit themselves to an ISO 22000 Approach?
  6. Who Should Use ISO 22000:2005?
  7. Why Use ISO 22000:2005?
  8. ISO 22000 and HACCP
  9. Codex Alimentarius
  10. Key Elements and Benefits of ISO 22000

9 ISO 22000-2005 – Structure

  1. Economic Loss due to Food Borne Illness
  2. ISO 22000: 2005 Clauses
  3. FSMS Documentation Structure
  4. Food Safety Team Structure
  5. Food Safety Manual
  6. Mandatory Procedures
  7. Standard Operating Procedures (SOP)/Work Instructions
  8. HACCP Pre-steps Related Documents
  9. HACCP Principles Related Documents
  10. Miscellaneous Documents
  11. Formats and Records

10 Clause-wise interpretation of ISO 22000- 2005

  1. Clause 1: Scope
  2. Clause 2: Normative References
  3. Clause 3: Terms and Definitions
  4. Clause 4: Food Safety Management System
  5. Clause 5: Management Responsibility
  6. Clause 6: Resource Management
  7. Clause 7: Planning and Realization of Safe Products
  8. Clause 8: Validation, Verification and Improvement of the FSMS

11 ISO 22000-2005-Case Studies

  1. Kick-off meeting
  2. Introduction to the standard
  3. Formation of food safety team
  4. Description of product and its intended use
  5. PRP (Pre-requisite programme)
  6. Flow diagrams, process steps and control measures
  7. Control measure assessment
  8. Verification of food safety management system
  9. Traceability system
  10. External communication
  11. Internal communication
  12. Management Reviews

12 An Overview and Requirements of ISO 17025

  1. Introduction to the ISO/IEC 17025 Standard
  2. Scope of ISO/IEC 17025
  3. Normative References
  4. Terms and Definitions
  5. General Requirements
  6. Structural Requirements
  7. Resource Requirements
  8. Process Requirements
  9. Management System Requirements

13 Requirements specific to Food testing laboratories – Physical and chemical Parameters

  1. Introduction
  2. Quality and Safety Requirements of Food Products
  3. Chemical and Physical Testing Requirements of Food Products
  4. Laboratory Quality Management System
  5. Management Requirements (Clause 4 of ISO 17025)
  6. Technical Requirements (Clause 5 of ISO 17025)
  7. Traceability of Measurement
  8. Sampling
  9. Handling Test and Calibration Items
  10. Assuring the Quality of Test and Calibration Results

14 Requirements specific to Food testing laboratories – Biological parameters

  1. Introduction
  2. Quality and Safety Requirements of Food Products
  3. Biological Testing Requirements of Food Products

15 General topics- related to Food testing laboratories

  1. Method Validation
  2. Ruggedness
  3. Uncertainty of Measurement
  4. International Accreditation Aspects

16 BRC Food and BRC/IOP Standards – An Overview

  1. BRC Global Standard – Food (Issue 5, January 2005)
  2. Introduction to BRC Food Standard
  3. Legislative Requirements
  4. Benefits of the BRC Global Standard – Food
  5. Principles of the BRC Global Standard – Food
  6. The Standard Technical Advisory Committee
  7. Scope of the BRC Global Standard – Food
  8. The Format of the BRC Global Standard – Food
  9. Application
  10. Structure and Interpretation of the Standard
  11. BRC / IOP Global Standard Issue 3 2001 (Food Packaging and Other Packaging Materials)
  12. IOP: The Institute of Packaging
  13. BRC/IOP Relationship
  14. Benefits of BRC/IOP Packaging Standard
  15. Principles of BRC/IOP Packaging Standard
  16. Application
  17. Structure of BRC / IOP Global Standard – Food Packaging and Other Packaging Materials

17 International Food Standard

  1. Background of the IFS
  2. Service Protocol of the IFS ISSUE 5
  3. Contractual Arrangements – Selection of Certifying Body
  4. Audit Notification
  5. Scope of the Audit
  6. Audit Flow – Preparing the Audit Plan
  7. Level Determination – KO, Major NC’s, NA
  8. Scores, Issuing the Audit Report and Certification
  9. Audit Frequency
  10. Audit Report
  11. Awarding of Certificate
  12. Distribution of the Audit Report
  13. Supplementary Action
  14. Appeal Procedure
  15. Complaints
  16. IFS – Catalogue of Requirements
  17. Management of Quality System
  18. Management Responsibility
  19. Resource Management
  20. Product Realization
  21. Measurements, Analysis and Improvements
  22. Requirements for Certification Bodies and Auditors
  23. Report

18 SQF 1000 And SQF 2000

  1. SQF 1000
  2. Interpretation of SQF 1000 Standard
  3. SQF 2000
  4. Interpretation of SQF 2000 Standard
  5. Let Us Sum Up

19 Global GAP and India GAP

  1. Potential Benefits and Challenges Related to Good Agricultural Practices (GAP)
  2. Description of the FAO/GAPs
  3. USDA GAP/GHP Programme
  4. Global GAP
  5. India GAP