Internal Audit & Compliance Guide 12 min read

The types of quality audits, explained

System, process or product? First, second or third party? ISO 9001, IATF 16949 or EHS? Quality audits are classified on three axes at once — here is the map that makes every named audit type fall into place.

Vidya Kathare July 18, 2026 12 min read
Three axes of classification
A
By subject
System · process · product
What
B
By relationship
First · second · third party
Who
C
By standard
ISO 9001 · IATF · 14001 · 45001
Against
+
Named types
Layered, supplier, fire, customer
One engine

The short answer

Quality audits are classified three ways at once, and any real audit is a point on all three axes. By subject an audit is a system audit, a process audit or a product audit. By relationship it is a first-party, second-party or third-party audit. And by standard it is run against ISO 9001, IATF 16949, ISO 14001, ISO 45001 or another framework. So a single audit might be, for example, a process audit (subject), conducted first-party (relationship), against IATF 16949 (standard). Understanding the three axes is what stops teams confusing an internal audit with a system audit — they are answers to different questions.

Why the confusion is so common
“Internal audit,” “system audit” and “ISO 9001 audit” sound like three names for the same thing. They are not — they describe the same audit from three different angles: who runs it, what it examines, and which standard it is judged against.
Get the three axes straight and every audit type below falls neatly into place.

Axis 1 — by subject: system, process, product

This is the ISO 19011 classification of what the audit examines, and it is the most useful distinction on the shop floor:

System audit

Examines whether the management system as a whole conforms to a standard — documented information, responsibilities, objectives and the interaction of processes across the organisation.

Whole system

Process audit

Examines a single process against its requirements — inputs, controls, parameters and outputs. Turtle-diagram thinking: does the process consistently produce a conforming result?

One process

Product audit

Examines a finished or in-process part against its specification and control plan — dimensions, parameters, samples and defect grades. The audit that happens at the line, not in a meeting room.

Parameter checks

The three nest: a product audit checks the output, a process audit checks the machine that made it, and a system audit checks the management framework that governs both. Automotive standards such as IATF 16949 explicitly require all three layers, which is why the same engine has to handle a clause-based system audit and a parameter-based product audit equally well.

Axis 2 — by relationship: first, second, third party

This axis describes who audits whom, and it maps directly onto the difference between internal and external audits:

PartyWho audits whomAlso called
First partyYou audit your own management systemInternal audit
Second partyYou audit a supplier, or a customer audits youSupplier audit / customer audit
Third partyAn independent registrar audits you for a certificateCertification-body audit

The practical point is that one organisation is on both ends of this axis. You conduct first-party internal audits and second-party supplier audits; you host second-party customer audits and third-party certification-body audits as the auditee. A capable system handles both directions — the findings a customer or registrar raises against you are tracked to closure with the same discipline as the findings you raise yourself.

Axis 3 — by standard

The third axis is the criteria the audit is judged against. Because the standard lives in the checklist template, not in the software, one system can carry a different clause-mapped template for every framework a manufacturer holds:

  • ISO 9001 — the quality-management-system baseline; internal audits check each process against the standard's clauses and the organisation's own procedures.
  • IATF 16949 — the automotive extension of ISO 9001; adds layered process audits, mandatory product audits and stricter corrective-action rules.
  • ISO 14001 — environmental management; audits check environmental aspects, impacts, legal compliance and operational controls.
  • ISO 45001 — occupational health and safety; audits check hazard controls, safe systems of work and worker participation.

Manufacturers certified to several of these run an integrated audit programme — one calendar, one auditor pool and one non-conformance register spanning quality, environment and safety, with a template per standard on a shared plan and closure engine.

Run every audit type on one engine?

See a system audit, a process audit and a shop-floor product audit — plus supplier and hosted customer audits — all on one calendar with one closure workflow. 30 minutes, on your standards.

Get a demo

Layered, supplier, fire and other named audits

Beyond the three axes, several named audit types come up constantly in Indian manufacturing. Each is really just a subject-plus-party-plus-standard combination with its own checklist:

  • Layered process audit (LPA) — the same short process audit repeated frequently by multiple layers of management, an IATF-favoured way to keep standard work honest between full audits.
  • Supplier / vendor audit — a scored second-party assessment of a vendor's quality system and process capability, used to qualify, rate and re-audit the supply base.
  • Customer audit (hosted) — your plant audited by a customer, often an OEM, against their specific requirements; you are the auditee and must close their findings.
  • Certification-body audit (hosted) — the third-party registrar's certification and surveillance visits.
  • Fire and safety audit — a statutory-compliance audit against a fire-safety checklist (extinguisher and hydrant coverage, emergency exits and signage, electrical safety, hot-work permits, evacuation drills, fire-NOC items), run through the identical plan-conduct-close pipeline.

Because an audit type is simply a template plus a classification, adding one — a new customer's format, a fire-safety audit, a new standard — is configuration, not a code change. That is what lets a single system stay the home for every audit a manufacturer runs.

There are not twenty kinds of audit to buy twenty tools for. There are three axes and one engine — and every named audit type is a point where the three axes cross.
Illustrative — IATF 16949 plant, full audit stack

All three layers, on one calendar

An automotive plant certified to IATF 16949 must run system audits against the standard's clauses, process audits on each manufacturing process, and product audits at the line — plus host OEM customer audits and the registrar's surveillance visits, and audit its own suppliers. On one system, each is a template of the right subject, run first- or second-party, against the right standard; all share the annual calendar, the competency-gated auditor pool and the same closure workflow, so the quality head sees planned-versus-conducted-versus-closed across every type in one place.

3
subject types: system, process, product
3
party types: first, second, third
1
shared plan & closure engine

How Fast Audit Software handles every type

Fast Audit Software models an audit type as a reusable checklist template plus a classification, so system, process, product, supplier, hosted customer and certification-body audits — and fire/safety audits — all run on the same plan, competency, checklist-entry and closure pipeline, for ISO 9001 and IATF 16949 and ISO 14001/45001. Product audits additionally capture parameter checks, sample readings and defect grades against the control plan. It is built by Improsys in Pune and runs cloud or on-premise. For the wider picture, start with what audit management software is.

Frequently asked questions

What are the main types of quality audits?

Quality audits are classified on three axes at once. By subject, an audit is a system audit (the whole management system against a standard), a process audit (one process against its requirements) or a product audit (a part against its specification and control plan). By relationship, it is a first-party audit (you audit yourself, i.e. internal), a second-party audit (you audit a supplier, or a customer audits you) or a third-party audit (an independent registrar audits you for certification). By standard, it is run against ISO 9001, IATF 16949, ISO 14001, ISO 45001 or another framework. Any real audit is a point on all three axes.

What is the difference between a system, process and product audit?

A system audit examines whether the whole management system conforms to a standard — its documented information, responsibilities, objectives and the interaction of processes. A process audit examines a single process against its requirements: inputs, controls, parameters and outputs, asking whether it consistently produces a conforming result. A product audit examines a finished or in-process part against its specification and control plan, checking dimensions, parameters, samples and defect grades. They nest: the product audit checks the output, the process audit checks how it was made, and the system audit checks the framework governing both.

What are first-party, second-party and third-party audits?

First-party audits are internal audits you conduct on your own management system. Second-party audits are between a customer and supplier — you audit your suppliers, and your customers audit you. Third-party audits are conducted by an independent certification body or registrar to grant or maintain a certificate such as ISO 9001 or IATF 16949. The same organisation both conducts audits (first-party internal, second-party supplier) and hosts them as the auditee (second-party customer, third-party certification).

Which quality standards require internal audits?

All ISO management-system standards require internal audits at planned intervals, including ISO 9001 (quality), IATF 16949 (automotive quality), ISO 14001 (environment) and ISO 45001 (occupational health and safety). IATF 16949 goes further than most, explicitly requiring layered process audits, manufacturing process audits and product audits in addition to the system audit. Because the standard lives in the checklist template rather than the software, one audit management system can carry a separate clause-mapped template for each framework a manufacturer holds.

Is a fire safety audit a type of quality audit?

A fire and safety audit uses the same audit machinery — a checklist template, a plan, an assigned auditor, findings and corrective-action closure — but its criteria are statutory fire-safety requirements rather than a quality standard: extinguisher and hydrant coverage, emergency exits and signage, electrical safety, hot-work permits, evacuation drills and fire-NOC items. Because an audit type is just a template plus a classification, a fire-safety audit runs through the identical plan-conduct-close pipeline as a quality audit, which is why the same system can host both.

One engine for every audit type you run

A 30-minute Fast Audit Software demo shows system, process, product, supplier and hosted customer audits on one calendar and one closure workflow — on your own standards.

Get a demo
No commitment. No slides. Your audit programme on screen.