Training module

Third-Party Auditing

Navigate accreditation, the certification ecosystem, the audit lifecycle, impartiality boundaries and certification decision interfaces

Cross-disciplineManagement System Auditor
Auditor working on laptop with symbolic overlays signaliding third-party audit context

Do you struggle to understand the unique governance and constraints of audits conducted by certification bodies?

Evaluate supplier evidence under real-world limitations using triangulation and consistency checks

Overview

What this module is about

Audits conducted by certification bodies differ fundamentally from internal audits, operating within a stringent accreditation-driven system that mandates independence and strict separation of audit activity from certification decisions.

This module provides a practical orientation to this complex ecosystem. Participants will learn how accreditation bodies and certification bodies interact, understand the full certification cycle from Stage 1 and Stage 2 through surveillance and recertification, recognise how impartiality is maintained, and clarify how lead auditors interface with review, decision, surveillance, and complaints mechanisms, enabling effective engagement without relying on proprietary procedures.

Audience

Who it is for

Management system implementers and coordinators

Executives and department heads accountable for management system performance

Those responsible for processes, policies, assets, risks and controls

Auditors seeking insight into management-side practice, not audit technique

Consultants working on management system design, governance or improvement

Decision supportIs this module for you?

It is a good fit if you…

work with or within audits conducted by certification bodies and want to understand how they are governed.

struggle to distinguish internal audits from Stage 1, Stage 2, surveillance, and recertification audits.

need clarity on independence, impartiality, and decision separation.

interact with certification bodies and want to avoid role confusion.

are transitioning into third-party auditing and need context, not CB-specific procedures.

It may not be the best fit if you…

already have a solid understanding of the accreditation–certification ecosystem.

are not involved in audits conducted by certification bodies or CB interactions.

need audit execution, interviewing, or reporting skills.

are looking for a specific certification body’s proprietary procedures.

Agenda

What is taught

10 parts
01What makes third-party audits different

How audits conducted by certification bodies differ from internal audits in purpose and constraints, including independence, impartiality, and the non-consultancy boundary

02Ecosystem and governance landscape

How accreditation bodies, certification bodies, standards, schemes, and sector regulations interact, and how accreditation expectations shape governance, oversight, and consistency in certification activities

03Roles, accountability, and decision separation

How roles are separated across audit, review, and certification decision functions, what auditors may and may not do in client interactions, and where the audit sits within the certification body's controlled process flow

04Competence and impartiality management in certification bodies (CBs)

How CBs manage auditor competence and impartiality at a system level, including qualification logic, assignment constraints, conflict handling, and behavioural expectations

05Audit lifecycle and stage logic

How Stage 1, Stage 2, surveillance, and recertification audits differ in intent, outputs, and limits, and what remains stable across the certification cycle

06Scope, boundaries, and auditability in a certification context

How scope statements, boundaries, exclusions, and multi-site structures are treated in audits conducted by certification bodies, and what “consistent coverage” means

07Impartiality in practice

How auditors recognise and manage common pressure points such as expectations of “helpfulness”, commercial sensitivities, and conflicts, while maintaining professional distance and constructive engagement

08Certification-oriented outputs

How outputs from audits conducted by certification bodies support objective, decision-ready conclusions, with clear separation between evidence, findings, and improvement opportunities, without drifting into consultancy

09Challenges, escalation paths, and complaint governance

How disagreements, complaints, and appeals are positioned at a high level, and how auditors are expected to act when constraints limit access, evidence, or time

10Case-based workshop

Applying the learned concepts, methods, and approaches in a realistic case setting

Outcomes

Learning outcomes

01

Explain how accreditation shapes certification body governance and third-party audit constraints

02

Describe the typical certification pathway and where audit activity interfaces with review and certification decisions

03

Distinguish the intent of Stage 1, Stage 2, surveillance, and recertification at a practical level

Recognise common impartiality and non-consultancy risks and define appropriate boundary-respecting responses

Distinguish the intent of Stage 1, Stage 2, surveillance, and recertification at a practical level

Brief internal stakeholders on what to expect from certification auditors and what requests are inappropriate

Navigate common friction points using appropriate escalation and complaint pathways

Materials

The content and the assessment

Written module

The full content in writing, complete in itself. Videos are recorded for parts of it as an alternative way through, and the written module always carries everything.

Exercises

Graded work on the case organisation's own registers: structured answers checked against the encoded case, written answers scored against a rubric traced to it, with a trainer holding the final word on every assessed item.

On completion

The assessed exercises must be passed before the certificate is issued.

Scheduling

No public run of Third-Party Auditing is scheduled at the moment. Tell us you are interested and we will let you know when the next one opens, or discuss running it in-house.

Module facts

Module ID
HAM-AG-AC-06
Download fact sheet (PDF, 4.7 MB) →

Case organisation

You work inside a company that already has the problem

Exercises run on one case organisation, carried across modules rather than restarted, so what you build here is what the next module finds.

Northstar Integrated Services AG is a group headquartered in Zurich, providing digital operations platforms and managed services to regulated organisations across Europe. It has not always been that. It began in 2008 as a field-operations firm of about twenty-five people, and what first forced documented decisions and named accountability on it was not growth but a single regulated customer. It now runs an acquired business in Poland and the Czech Republic through a subsidiary that kept its own legal identity, which is where the interesting failures live: group instruments rolled out operationally and never put in force by the governing bodies of the subsidiary itself.

Linked registers
Organisation and people, risks, objectives, policies and documents, findings and reviews, third parties, processes

Not a case study
Nothing is summarised for you; the evidence is where it would really be

It has a history
The organisation has a timeline, and modules enter it at different points, so a structure can be studied before it broke as well as after

It crosses borders
A Swiss parent, an acquired operating business in Poland and the Czech Republic under its own legal entity, and customers in several jurisdictions

Why it matters

Judgement is not trained on tidy examples, and it is not trained on a fresh one each week. Northstar is deliberately untidy, and modules enter it at different points of its history, so you see a governance structure being built, outgrown and rebuilt rather than a finished one. What you decide in one module is what the next one finds.

How we teach →

Delivery & dates

How this module reaches you

Delivered live online, combining conceptual framing, discussion, case work and direct interaction with the trainer. In-house and contextualised delivery is available on request.

No public run is scheduled at the moment. Most modules run on request as well as on the public calendar, so tell us the timing you need.

Want this module scheduled?

We will tell you when the next run is scheduled, or run this module in-house with your own case material.

Not sure it is the right module?

Describe your context in a short message and we will tell you honestly.

No obligation

Tell us what would work and we will come back with dates, or with an in-house proposal if you would rather run this for a group on your own management system.
About Third-Party Auditing · HAM-AG-AC-06

No account needed. We reply personally, usually within a working day. Sending is not switched on yet, so write to us in the meantime: contact us.

Decision support

Describe your role and your context in a short message and we will tell you honestly whether this module is the right one, or point you at a better fit.
About Third-Party Auditing · HAM-AG-AC-06

No account needed. We reply personally, usually within a working day. What happens to your message is set out in the privacy policy.