Hosting vs conducting an audit
Almost everything written about auditing assumes you are the auditor — planning the audit, running the checklist, raising findings. But some of the highest-stakes audits a manufacturer faces are ones where it is the auditee: a customer audits your plant, or a certification body audits your management system. Here the discipline inverts. The challenge is not to find issues; it is to prove control — to produce, on demand, evidence that your system works and your findings close.
This is what "hosting" an audit means, and it is a genuinely different skill from conducting one. A conducted audit tests someone else's process; a hosted audit tests your own readiness and, indirectly, your entire audit programme. If that programme is real and current, hosting is calm retrieval. If it is a stack of spreadsheets, hosting is a week of panic reconstructing records the night before the auditor arrives.
Customer and certification-body audits
Two hosted audit types matter most to a manufacturer, and both sit opposite your own internal and supplier audits.
Customer audit
An OEM or customer audits your plant against their requirements and customer-specific rules. You are the auditee; the findings they raise become your corrective actions.
Second-party, hostedCertification-body audit
An accredited registrar audits your management system to grant or maintain certification to ISO 9001, IATF 16949, ISO 14001 or ISO 45001, on a fixed cycle.
Third-party, hostedWhat they both want
Evidence your system runs: the audit plan, conducted audits, findings and their closure, competency records and reports — retrievable on demand.
Evidence on demandThe crucial point is that both auditors ask for the same underlying evidence, and it is evidence your internal-audit system already produces. A customer wants to see you audit and control your processes; a registrar wants the same, mapped to the standard's clauses. Hosting these audits as their own types — so their findings live in your register too — is the difference between a joined-up programme and a set of disconnected events. This mirrors the outbound direction covered in the supplier audit guide: there you are the customer auditing a vendor; here someone is the customer auditing you.
The certification audit cycle
A certification-body audit is not a single event but a cycle, and understanding it removes much of the fear. For ISO and IATF certification the pattern is consistent:
| Stage | What happens | Typical timing |
|---|---|---|
| Stage 1 (readiness) | The registrar checks your system is documented and ready — a readiness review | Before initial certification |
| Stage 2 (certification) | A full audit of the system in operation against the standard; findings raised | Weeks after Stage 1 |
| Surveillance | A sampled audit to confirm the system is maintained and improving | Annually |
| Recertification | A full re-audit to renew the certificate | Typically every three years |
Because the cycle is predictable, readiness should be a steady state, not a scramble. The internal-audit programme is the thing the registrar is really testing: clause 9.2 of ISO 9001 and IATF 16949 requires you to run internal audits at planned intervals, and the surveillance auditor will sample your audit plan, your conducted audits, your findings and your closure to confirm you actually do. Keep that current and each surveillance visit is a review of work already done.
Rebuilding audit evidence the week before the registrar visits?
See how a live audit programme makes hosting a customer or certification audit into simple retrieval — plan, findings, closure and competency, one search away. 30 minutes, your own records.
Why hosted audits cause panic
The panic around a customer or certification audit is almost never about the standard — it is about retrieval. Three failure modes cause it, and all three are symptoms of a fragmented programme.
1. The evidence exists but cannot be found
The audit was done, the NC was closed, the auditor was qualified — but the checklist is in one person's laptop, the closure is in an email thread, and the competency certificate is in a drawer. When the auditor asks, the record cannot be produced in the moment, and an audit that could not be evidenced may as well not have happened.
2. Findings from the last audit are still open
Nothing unsettles a surveillance auditor like an open non-conformance from the previous visit with no closure trail. Without due-date reminders and a closure workflow, findings age quietly until the auditor is at the door — and a repeat of a previously raised issue is worse still.
3. The programme cannot be shown as a whole
Asked "show me your audit programme," a team on spreadsheets shows fragments. A registrar wants to see planned versus conducted versus closed, coverage across the year and repeat-finding trends — a coherent picture, not a folder of files. If the picture cannot be assembled quickly, confidence drops before a single clause is examined.
What audit-readiness actually looks like
Audit-readiness is not a binder assembled for the occasion; it is a live programme whose byproduct is evidence. When the whole chain from plan to closure is maintained on one system, hosting becomes retrieval. Concretely, a ready plant can produce on demand:
- The annual audit plan and calendar, showing planned coverage against the standard's requirement to audit at planned intervals.
- Every conducted audit's answered checklist, with conformance, clause and observations, retrievable by area and date.
- The full NC history — each finding, its grade, its corrective action and its multi-role closure sign-off with dates.
- The auditor-competency records — who is qualified for which audit type, with evidence attached — the exact question a registrar asks.
That list is not a special preparation. It is simply what a properly run audit management system holds all the time. The plant that runs its internal audits well is, by definition, ready to host — which is why the best certification-audit preparation is not a mock audit but a real programme.
Closing findings raised against you
When a customer or registrar raises a finding, it is your non-conformance now, and it must be driven to closure with the same discipline as one you raised yourself. The mistake is to keep externally raised findings in a separate tracker; the right move is to log them in the same register, as their own audit type, and run them through the same loop.
Keeping hosted findings in the same register means nothing raised by a customer or registrar is ever lost, and the closure trail is ready for the follow-up. A major finding can escalate into Fast Quality's formal 8D / CAPA workflow, and reminders keep the response on schedule — because a certification NC left open past its due date is how certificates get suspended.
How Fast Audit hosts external audits
Fast Audit Software hosts customer and certification-body audits as their own audit types on the same platform that runs your internal programme, so the evidence is already there and the findings live in one register. Mapping readiness to the product:
Run this way across a group of plants, every site is audit-ready in the same way, and the same instance that hosts your OEM customer audits also runs your EHS and supplier programmes — one system, one register, always ready.
Frequently asked questions
What is the difference between conducting and hosting an audit?
When you conduct an audit you are the auditor — you plan it, run the checklist and raise findings, as in an internal, product or supplier audit. When you host an audit you are the auditee — a customer or a certification body audits you, and your job is to produce evidence and answer questions on demand, then close the findings they raise against you. Hosting is a different discipline: the challenge is not finding issues but proving control and having every record ready without a scramble.
What is a certification-body audit?
A certification-body audit is a third-party audit conducted by an accredited registrar to certify or maintain your certification to a standard such as ISO 9001, IATF 16949, ISO 14001 or ISO 45001. It follows a cycle — an initial certification audit in two stages, then annual surveillance audits, then a recertification audit, typically every three years. The registrar samples your management system against the standard, raises non-conformances for gaps, and requires corrective action and closure evidence.
How do you prepare for a customer or certification audit?
The most reliable preparation is a live internal-audit programme rather than a pre-audit cleanup. If your audit calendar, findings, corrective-action closure and auditor-competency records are maintained continuously on one system, hosting an external audit becomes retrieval, not reconstruction: the auditor asks for evidence of an audit, a closed NC or a competency record and it is one search away. A system that keeps the whole chain from plan to closure current is what lets a plant host a customer or registrar calmly.
How are findings from a customer or certification audit handled?
Findings raised against you should be logged as non-conformances of their own audit type — customer audit or certification-body audit — graded major or minor, and driven to closure through the same corrective-action workflow as your internal findings. The area submits containment, root cause and corrective and preventive action with a due date; a coordinator reviews; and closure is verified with evidence. Keeping externally raised findings in the same register as internal ones means nothing is lost and the trail is ready for the follow-up.
Why keep hosted audits in the same system as internal audits?
Because the evidence a customer or registrar wants is exactly what your internal-audit system already holds — the audit plan, conducted checklists, findings, closure history, competency records and reports. Hosting the customer and certification-body audits as their own types in the same system means one register, one closure workflow and one place to retrieve evidence, so you can show a consistent, current picture and close externally raised findings with the same discipline as your own.
Does Fast Audit support customer and certification-body audit types?
Yes. Alongside system, process, product and supplier audits, Fast Audit hosts customer audits and certification-body audits as their own audit types on the same engine. Their findings are logged, graded and driven to verified closure in the same NC register as your internal findings, and the audit plan, conducted checklists, closure history and competency records are retrievable on demand — so hosting an external audit is retrieval, not a fire drill.
