Industries — Customer & Certification Audits 12 min read

Hosting customer & certification-body audits without panic

When a customer or a registrar audits you, the job changes from finding issues to proving control. This guide is about being the auditee — evidence on demand, NC history, closure records and readiness — so a customer or ISO certification audit is retrieval, not a fire drill.

Vidya Kathare · July 18, 2026 12 min read Updated July 2026
Audit-ready, on demand
01
Audit plan
Evidence your programme runs
Ready
02
Conducted audits
Answered checklists, retrievable
On file
03
NC history
Findings, closure, sign-off
Traceable
04
Competency
Who is qualified, evidenced
Proven
05
Host & close
Their findings, driven to closure
Closed

Hosting vs conducting an audit

Almost everything written about auditing assumes you are the auditor — planning the audit, running the checklist, raising findings. But some of the highest-stakes audits a manufacturer faces are ones where it is the auditee: a customer audits your plant, or a certification body audits your management system. Here the discipline inverts. The challenge is not to find issues; it is to prove control — to produce, on demand, evidence that your system works and your findings close.

This is what "hosting" an audit means, and it is a genuinely different skill from conducting one. A conducted audit tests someone else's process; a hosted audit tests your own readiness and, indirectly, your entire audit programme. If that programme is real and current, hosting is calm retrieval. If it is a stack of spreadsheets, hosting is a week of panic reconstructing records the night before the auditor arrives.

The core idea
You cannot prepare for a certification audit in the week before it. You can only reveal, in that week, whether your audit programme was real all year.
The evidence a registrar or customer asks for is exactly what a live internal-audit system already holds. Hosting well is not a special project — it is the natural output of running the programme properly every day.

Customer and certification-body audits

Two hosted audit types matter most to a manufacturer, and both sit opposite your own internal and supplier audits.

Customer audit

An OEM or customer audits your plant against their requirements and customer-specific rules. You are the auditee; the findings they raise become your corrective actions.

Second-party, hosted

Certification-body audit

An accredited registrar audits your management system to grant or maintain certification to ISO 9001, IATF 16949, ISO 14001 or ISO 45001, on a fixed cycle.

Third-party, hosted

What they both want

Evidence your system runs: the audit plan, conducted audits, findings and their closure, competency records and reports — retrievable on demand.

Evidence on demand

The crucial point is that both auditors ask for the same underlying evidence, and it is evidence your internal-audit system already produces. A customer wants to see you audit and control your processes; a registrar wants the same, mapped to the standard's clauses. Hosting these audits as their own types — so their findings live in your register too — is the difference between a joined-up programme and a set of disconnected events. This mirrors the outbound direction covered in the supplier audit guide: there you are the customer auditing a vendor; here someone is the customer auditing you.

The certification audit cycle

A certification-body audit is not a single event but a cycle, and understanding it removes much of the fear. For ISO and IATF certification the pattern is consistent:

StageWhat happensTypical timing
Stage 1 (readiness)The registrar checks your system is documented and ready — a readiness reviewBefore initial certification
Stage 2 (certification)A full audit of the system in operation against the standard; findings raisedWeeks after Stage 1
SurveillanceA sampled audit to confirm the system is maintained and improvingAnnually
RecertificationA full re-audit to renew the certificateTypically every three years

Because the cycle is predictable, readiness should be a steady state, not a scramble. The internal-audit programme is the thing the registrar is really testing: clause 9.2 of ISO 9001 and IATF 16949 requires you to run internal audits at planned intervals, and the surveillance auditor will sample your audit plan, your conducted audits, your findings and your closure to confirm you actually do. Keep that current and each surveillance visit is a review of work already done.

Rebuilding audit evidence the week before the registrar visits?

See how a live audit programme makes hosting a customer or certification audit into simple retrieval — plan, findings, closure and competency, one search away. 30 minutes, your own records.

Get a demo

Why hosted audits cause panic

The panic around a customer or certification audit is almost never about the standard — it is about retrieval. Three failure modes cause it, and all three are symptoms of a fragmented programme.

1. The evidence exists but cannot be found

The audit was done, the NC was closed, the auditor was qualified — but the checklist is in one person's laptop, the closure is in an email thread, and the competency certificate is in a drawer. When the auditor asks, the record cannot be produced in the moment, and an audit that could not be evidenced may as well not have happened.

2. Findings from the last audit are still open

Nothing unsettles a surveillance auditor like an open non-conformance from the previous visit with no closure trail. Without due-date reminders and a closure workflow, findings age quietly until the auditor is at the door — and a repeat of a previously raised issue is worse still.

3. The programme cannot be shown as a whole

Asked "show me your audit programme," a team on spreadsheets shows fragments. A registrar wants to see planned versus conducted versus closed, coverage across the year and repeat-finding trends — a coherent picture, not a folder of files. If the picture cannot be assembled quickly, confidence drops before a single clause is examined.

What audit-readiness actually looks like

Audit-readiness is not a binder assembled for the occasion; it is a live programme whose byproduct is evidence. When the whole chain from plan to closure is maintained on one system, hosting becomes retrieval. Concretely, a ready plant can produce on demand:

  • The annual audit plan and calendar, showing planned coverage against the standard's requirement to audit at planned intervals.
  • Every conducted audit's answered checklist, with conformance, clause and observations, retrievable by area and date.
  • The full NC history — each finding, its grade, its corrective action and its multi-role closure sign-off with dates.
  • The auditor-competency records — who is qualified for which audit type, with evidence attached — the exact question a registrar asks.

That list is not a special preparation. It is simply what a properly run audit management system holds all the time. The plant that runs its internal audits well is, by definition, ready to host — which is why the best certification-audit preparation is not a mock audit but a real programme.

Closing findings raised against you

When a customer or registrar raises a finding, it is your non-conformance now, and it must be driven to closure with the same discipline as one you raised yourself. The mistake is to keep externally raised findings in a separate tracker; the right move is to log them in the same register, as their own audit type, and run them through the same loop.

Closing an externally raised finding
1
Log it as a hosted-audit finding
Record the customer or CB finding against its audit type, with the clause, the grade and the auditor's wording.
2
Area submits corrective action
Containment, root cause and corrective and preventive action with a due date — for a major finding, a formal 8D.
3
Coordinator reviews
The action is checked for adequacy before it is submitted back to the customer or registrar.
4
Verify and evidence
Effectiveness is confirmed with objective evidence — the same proof the registrar will want at the follow-up.
5
Close and retain
The finding closes in the register, and the trail is retained for the surveillance or recertification review.

Keeping hosted findings in the same register means nothing raised by a customer or registrar is ever lost, and the closure trail is ready for the follow-up. A major finding can escalate into Fast Quality's formal 8D / CAPA workflow, and reminders keep the response on schedule — because a certification NC left open past its due date is how certificates get suspended.

How Fast Audit hosts external audits

Fast Audit Software hosts customer and certification-body audits as their own audit types on the same platform that runs your internal programme, so the evidence is already there and the findings live in one register. Mapping readiness to the product:

1
Keep the programme live. Run your internal audits on the annual plan and calendar so the plan, coverage and conducted audits are always current — the first thing a registrar samples.
2
Retrieve evidence on demand. Every conducted checklist, finding and closure record is stored on the shared document engine and retrievable by area, date and audit type — no reconstruction.
3
Prove competency instantly. The competency records show who is authorised for which audit type, with evidence — answering the registrar's question from one screen.
4
Host the audit as its own type. Log the customer or certification-body audit and the findings raised against you, graded and attributed, in the same NC register as your internal findings.
5
Close and report. Drive each externally raised NC to verified closure through the multi-role sign-off, with reminders, and show the whole programme on the dashboards and NC register.

Run this way across a group of plants, every site is audit-ready in the same way, and the same instance that hosts your OEM customer audits also runs your EHS and supplier programmes — one system, one register, always ready.

Keep going — the internal-audit library
Related guides on the audit programme, plus the product pages that show how Fast Audit Software implements each part.

Frequently asked questions

What is the difference between conducting and hosting an audit?

When you conduct an audit you are the auditor — you plan it, run the checklist and raise findings, as in an internal, product or supplier audit. When you host an audit you are the auditee — a customer or a certification body audits you, and your job is to produce evidence and answer questions on demand, then close the findings they raise against you. Hosting is a different discipline: the challenge is not finding issues but proving control and having every record ready without a scramble.

What is a certification-body audit?

A certification-body audit is a third-party audit conducted by an accredited registrar to certify or maintain your certification to a standard such as ISO 9001, IATF 16949, ISO 14001 or ISO 45001. It follows a cycle — an initial certification audit in two stages, then annual surveillance audits, then a recertification audit, typically every three years. The registrar samples your management system against the standard, raises non-conformances for gaps, and requires corrective action and closure evidence.

How do you prepare for a customer or certification audit?

The most reliable preparation is a live internal-audit programme rather than a pre-audit cleanup. If your audit calendar, findings, corrective-action closure and auditor-competency records are maintained continuously on one system, hosting an external audit becomes retrieval, not reconstruction: the auditor asks for evidence of an audit, a closed NC or a competency record and it is one search away. A system that keeps the whole chain from plan to closure current is what lets a plant host a customer or registrar calmly.

How are findings from a customer or certification audit handled?

Findings raised against you should be logged as non-conformances of their own audit type — customer audit or certification-body audit — graded major or minor, and driven to closure through the same corrective-action workflow as your internal findings. The area submits containment, root cause and corrective and preventive action with a due date; a coordinator reviews; and closure is verified with evidence. Keeping externally raised findings in the same register as internal ones means nothing is lost and the trail is ready for the follow-up.

Why keep hosted audits in the same system as internal audits?

Because the evidence a customer or registrar wants is exactly what your internal-audit system already holds — the audit plan, conducted checklists, findings, closure history, competency records and reports. Hosting the customer and certification-body audits as their own types in the same system means one register, one closure workflow and one place to retrieve evidence, so you can show a consistent, current picture and close externally raised findings with the same discipline as your own.

Does Fast Audit support customer and certification-body audit types?

Yes. Alongside system, process, product and supplier audits, Fast Audit hosts customer audits and certification-body audits as their own audit types on the same engine. Their findings are logged, graded and driven to verified closure in the same NC register as your internal findings, and the audit plan, conducted checklists, closure history and competency records are retrievable on demand — so hosting an external audit is retrieval, not a fire drill.

Be ready for every customer and certification audit

A 30-minute Fast Audit Software demo shows how a live audit programme makes hosting simple — the plan, conducted audits, findings and closure, and competency evidence retrievable on demand, with externally raised findings driven to verified closure in one register.

Get a demo
No commitment. No slides. Your audit-readiness on screen.