A second-party audit is an audit that an organization carries out at its own supplier or contracted party. Commonly known as a supplier audit.
Its purpose is to verify the supplier’s conformity to the contract, the standard and customer-specific requirements.
When is it needed?
A supplier audit may be needed even when the supplier is certified. Certification demonstrates general system conformity; it does not demonstrate that your specific requirements are met.
This obligation becomes pronounced for organizations that purchase special processes. If you source processes such as heat treatment, plating or welding externally, the responsibility for verifying the conformity of your supplier’s process control system is yours.
How is the programme set up?
Auditing all suppliers at the same frequency is not efficient. ISO 19011:2026 emphasizes planning the audit programme with the organization’s objectives, processes and priorities in mind.
Part criticality, the supplier’s past performance, length of the relationship and the nature of the process can be used as prioritization criteria.
Auditor competence
Personnel conducting second-party audits need to know both the audit methodology and the technical requirements of the process being audited. Filing a self-assessment received from the supplier does not count as verification.
Supplier auditing requires both methodology and technical knowledge. The ISO 19011 training covers the audit side; for the technical requirements specific to the process being audited, programmes such as the CQI-11 plating system assessment training are suitable. We can identify the right training together based on the process at your supplier.