Independent guide to OSHA 10 & 30 online Outreach training
Questions? support@oshaworkplacesafety.com  ·  Request course details
Internal Audit vs External Audit: 9 Key Differences
Home / Blog / Internal Audit vs External Audit: 9 Key Differences

Internal Audit vs External Audit: 9 Key Differences

17 min read

Key Takeaways

  • An internal audit is performed by or on behalf of the organization itself to check that its own systems are working. An external audit is performed by an independent party outside the organization to give assurance to someone else.
  • ANSI/ASSP Z10.0-2019 defines an audit as a systematic, independent, and documented process, and defines independence as not being responsible for the activity being audited.
  • First party means you audit yourself; second party means a customer audits you; third party means an accredited independent body audits you and can issue a certificate.
  • An OSHA inspection is enforcement with citations and penalties. An external audit is assurance, and the worst outcome is a major nonconformity and a suspended certificate.
  • OSHA's published policy says the agency will not routinely request self-audit reports at the start of an inspection, and that protection is tied to correcting what the audit found.
$16,550
OSHA maximum penalty per serious violation
$165,514
Maximum per willful or repeat violation
Feb 15
Annual deadline for OSHA VPP self-evaluations

Plenty of US employers still avoid writing down what their own safety walkthroughs find, on the theory that a documented hazard is evidence waiting to be used against them. That fear is not imagined, and it is not new. OSHA published a formal policy in 2000 specifically because employers believed inspectors would treat self-audit reports as road maps to citations. Understanding the difference between an internal audit vs external audit, and between an audit and an inspection, is what settles that fear. This guide is built on OSHA's published penalty schedule and self-audit policy, the Institute of Internal Auditors' Global Internal Audit Standards, ANSI/ASSP Z10.0-2019, and the audit requirements written into ISO 45001.

Internal Audit vs External Audit: The Short Answer

An internal audit is performed by or on behalf of the organization itself to check that its own systems are working. An external audit is performed by an independent party outside the organization to give assurance to someone else, whether that is a certification body, a customer, or shareholders. Same techniques, completely different purpose and audience.

Internal AuditExternal Audit
Performed byEmployees or a contractor acting for youAn independent outside party
Reports toAudit committee, board, or top managementCertification body, client, or shareholders
PurposeImprove the systemProvide assurance to others
Scope set byThe organizationA standard, contract, or law
FrequencyContinuous or on a rolling annual planFixed cycle, often annual
MandatoryOnly where a standard or contract requires itUsually yes, to keep a certificate or contract
OutputFindings and corrective actionsFormal opinion, certificate, or nonconformities
If it goes badlyInternal action planLost certificate or lost contract

What Is an Internal Audit?

An internal audit checks whether your management system does what your own documents say it does. It is a review you commission on yourself, and the findings belong to you.

ANSI/ASSP Z10.0-2019, the American national standard for occupational health and safety management systems, defines an audit as a systematic, independent, and documented process for gathering information and evaluating it objectively against defined criteria. Note the word documented. An undocumented walkthrough is not an audit under any recognized standard.

Who Runs It and Who They Report To

Internal auditors are usually employees, though smaller companies often hire an outside consultant to act as their internal auditor. Either way, the audit is done on the organization's behalf, which is what makes it internal.

Reporting lines are the part people get wrong. The Institute of Internal Auditors' Global Internal Audit Standards, which took effect on January 9, 2025, require the internal audit function to be positioned so it reports functionally to the board rather than to the managers whose work it examines. In a safety context, that means the person auditing the lockout program should not be reporting their findings only to the maintenance manager who owns it.

That positioning is being pushed further. In the IIA's 2025 North American Pulse of Internal Audit, surveyed between October and November 2024 with 85 percent of respondents based in the United States, 54 percent of chief audit executives described their function as almost fully or fully aligned with organizational strategy. Internal audit is moving from a checking function toward a strategic one, and safety audits are being pulled along with it.

What an Internal Audit Actually Looks For

Not paperwork. Objective evidence that the system works in practice:

  • Whether the written procedure matches what people on the floor actually do
  • Whether training records exist for everyone doing the task
  • Whether previous findings were closed out or quietly forgotten
  • Whether the controls listed in your risk assessment matrix are physically present and functioning

A good internal audit is uncomfortable. If yours never finds anything, it is not an audit, it is a formality.

What Is an External Audit?

An external audit is performed by someone with no stake in the result, for the benefit of a party outside your management chain.

Certification Bodies, Clients, and Regulators

Three very different groups run external audits, and they want different things:

  • 1. Certification bodies audit your management system against a standard such as ISO 45001 and issue or withhold a certificate
  • 2. Customers audit your site before awarding or renewing a contract, focused on whether you can deliver safely
  • 3. Insurers and corporate parents audit to price risk or confirm group standards

A regulator like OSHA sits outside all three. More on why that distinction matters below.

Stage 1, Stage 2, Surveillance, and Recertification

Certification audits follow a defined cycle that catches most first-timers by surprise:

  • 1. Stage 1 is a readiness review. The auditor checks your documentation, scope, and whether the system has been running long enough to produce records. Often done remotely.
  • 2. Stage 2 is the full audit. Interviews, site observation, and evidence sampling across everything in scope.
  • 3. Surveillance audits happen every six to twelve months and sample part of the system rather than all of it.
  • 4. Recertification comes around at the three-year mark and looks at the whole system again.

The mechanics of getting through that first cycle are covered in more detail in the guide to how ISO certification works.

Infographic comparing internal audit and external audit across purpose, independence, scope and reporting

The nine differences that decide which audit you are actually facing.

9 Key Differences Between Internal and External Audits

  • 1. Purpose. Internal audits exist to improve the system. External audits exist to prove something about it to an outside party.
  • 2. Who performs it. Internal audits are done by or for the organization. External audits are done by a party with no interest in the outcome.
  • 3. Independence. Under ANSI/ASSP Z10.0-2019, an internal auditor is independent of the activity being audited. An external auditor is independent of the entire organization, which is a much higher bar.
  • 4. Who receives the report. Internal findings go to the audit committee, board or top management. External findings go to the certification body, the client, or the shareholders.
  • 5. Who sets the scope. You choose what your internal audit covers. The standard, contract, or law dictates what the external audit covers.
  • 6. Frequency. Internal audits run continuously on a rolling plan. External audits arrive on a fixed schedule you do not control.
  • 7. Whether it is mandatory. Internal audits are required only where a standard or contract says so. External audits are the price of holding a certificate or a contract.
  • 8. What it produces. Internal audits produce findings and corrective actions. External audits produce a formal opinion, a certificate decision, or graded nonconformities.
  • 9. What failure costs. A bad internal audit costs you an action plan. A bad external audit can cost you the certificate, and with it, the customer who required it.

What the Standards Actually Require

Rather than argue about best practice, here is what four recognized authorities put in writing, and which type of audit each one is talking about.

AuthorityWhat it requiresAudit type
OSHA regulationsSpecific written programs, records and training. No general requirement to audit the whole systemNeither, but inspections test the result
OSHA VPPAn annual self-evaluation of the safety and health management system, submitted to the Regional VPP Manager by February 15 each yearInternal, and OSHA states it is not a compliance audit
ISO 45001, clause 9.2Internal audits at planned intervals, with an audit program based on risk and the results of previous auditsInternal, verified by a third party
ANSI/ASSP Z10.0-2019Regular monitoring, internal audits, incident investigation and management review, with auditors free of bias and conflict of interestInternal
IIA Global Internal Audit StandardsInternal audit positioned with functional reporting to the board, effective January 9, 2025Internal

The pattern is worth noticing. Every authority that mandates an audit mandates the internal one. External audits are driven by certificates and contracts, not by regulators.

First, Second, and Third Party Audits Explained

The internal versus external split is useful shorthand, but auditors actually use a three-way model that is more precise:

  • 1. First party audit. You audit yourself. This is the internal audit.
  • 2. Second party audit. A party with a commercial interest audits you, typically a customer auditing a supplier before a contract renewal.
  • 3. Third party audit. An accredited, independent body audits you against a standard and can issue a certificate. Nobody in the room has a commercial stake in the outcome.

The distinction matters commercially. A customer's second-party audit can be tough, but it cannot give you an ISO 45001 certificate. Only an accredited third party can, and only third party certificates are recognized on tender documents.

Diagram explaining first party, second party and third party audits and who performs each one

First, second, and third party audits, and who is standing on each side.

An Audit Is Not an OSHA Inspection

This is the confusion that keeps companies from auditing themselves at all, so it is worth being blunt about it.

Enforcement vs Assurance

An OSHA inspection is enforcement. It is usually unannounced, triggered by a complaint, a referral, a serious incident, or a programmed emphasis, and it can end in citations and monetary penalties. Per OSHA's published penalty schedule, a serious violation currently carries a maximum of $16,550, and a willful or repeat violation reaches $165,514. Failure to abate is charged per day past the abatement date.

An external audit is assurance. It is scheduled, you signed a contract for it, and the worst outcome is a major nonconformity and a suspended certificate. No fines, no citations. For what an actual enforcement visit involves, see the walkthrough of what to expect from an OSHA inspection.

What OSHA Can and Cannot Do With Your Audit Report

OSHA published its final policy on voluntary employer safety and health self-audits in the Federal Register on July 28, 2000, and it still stands. Under that policy, the agency will not routinely request self-audit reports at the start of an inspection, and will not use them as a means of identifying hazards to focus on during an inspection.

The policy also provides that where an employer identified a hazard through a voluntary self-audit and corrected it before an inspection, OSHA will not use the audit report as evidence of a willful violation.

Read the condition carefully, because it is the whole deal. The protection attaches to finding and fixing. An audit report full of open findings that nobody acted on is worse than no audit at all, because it documents that you knew.

The federal government runs a working example of exactly this model. Participants in OSHA's Voluntary Protection Programs are required to complete an annual self-evaluation of their safety and health management system and submit it to their OSHA Regional VPP Manager by February 15 each year. OSHA is explicit that this self-evaluation is not a compliance audit. It is a critical review of the program's effectiveness, written by the site itself, and sent to the regulator.

Safety manager reviewing an audit report and corrective action log at a US manufacturing facility

The protection in OSHA's policy attaches to the corrective action log, not the audit report.

How the Two Audits Work Together on a Real Safety Program

Internal and external audits are not rivals. The internal audit exists so that the external auditor never gets to be the first person who notices.

Sequence matters. Run the internal audit far enough ahead of the certification visit that corrective actions can actually be completed and verified, not just opened. Auditors can tell the difference between a closed action and a closed ticket.

A 12-Month Audit Calendar

A workable annual cycle for a mid-sized manufacturing site, built around the requirements in the table above:

  • 1. Q1 internal audit of high-risk processes: confined space, hot work, lifting operations, energy isolation. VPP sites complete the annual self-evaluation before the February 15 submission date.
  • 2. Q2 corrective actions verified and closed, then the surveillance audit from the certification body
  • 3. Q3 internal audit of the remaining system elements, including contractor management and emergency preparedness
  • 4. Q4 management review, next year's audit plan approved, objectives reset

High-risk processes get audited more often than once a year. Low-risk administrative elements can sit on an annual rotation. ISO 45001 clause 9.2 asks for exactly this: an audit program shaped by risk and by what previous audits found, which is what an HSE management system is designed to structure.

Who Is Allowed to Audit What

Two rules cause most of the friction, and both come straight from the standards:

  • Nobody audits their own work. ANSI/ASSP Z10.0-2019 defines auditor independence as not being responsible for the activity under audit and being free of bias and conflict of interest. The safety manager who wrote the confined space procedure cannot be the person who audits it. In a small company, cross-audit between departments, or bring someone in.
  • A consultant cannot build your system and then certify it. Accreditation rules prohibit a certification body from consulting on the same management system it certifies. Firms that offer to "get you certified" as a package are either subcontracting the audit or misrepresenting what they do.

An outside consultant acting as your internal auditor is perfectly legitimate. That is still a first party audit, because they are working on your behalf.

Is an Internal Audit Required by Law?

No general United States law requires a private employer to conduct a safety audit. OSHA requires specific programs, records, and training, but does not mandate a periodic audit of the whole system.

Three things change that answer in practice:

  • 1. ISO 45001 clause 9.2 requires certified organizations to run internal audits at planned intervals. No internal audit means no certificate. The clause structure is covered in the breakdown of ISO 45001 requirements.
  • 2. Voluntary programs with binding conditions. OSHA VPP participation carries the annual self-evaluation requirement described above, with a fixed submission deadline.
  • 3. Contracts. Many large customers and general contractors require documented internal audits as a condition of doing business, and some state plans and specific standards carry their own review requirements.

7 Audit Mistakes That Turn a Minor Finding Into a Major One

  • 1. Auditing the checklist instead of the risk. A generic template will confirm you have a procedure and never notice the procedure is wrong for your process.
  • 2. Recording opinions instead of objective evidence. "Training appears adequate" is not a finding. "Three of eight operators had no record of energy isolation training" is.
  • 3. Corrective actions that treat the symptom. Retraining one employee does not fix a procedure that nobody can follow.
  • 4. The same person auditing their own area. It fails the independence definition in Z10.0-2019 and any external auditor will spot it immediately.
  • 5. Findings that are opened and never closed. An aging open-findings list is the single fastest way to turn several minor nonconformities into one major one, and it removes the protection OSHA's self-audit policy offers.
  • 6. Skipping management review. The audit feeds the review. Without it the loop never closes and nothing changes at the resourcing level.
  • 7. Running the internal audit the week before the certification body arrives. There is no time to fix anything, and the auditor will notice the dates.

FAQ

Purpose and audience. An internal audit is run by or for the organization to improve its own systems. An external audit is run by an independent party to give assurance to someone outside the organization, such as a certification body or a customer.

The audit committee, the board, or top management, rather than the manager responsible for the area being audited. The IIA's Global Internal Audit Standards, effective January 9, 2025, require functional reporting to the board to protect independence.

The internal audit. It should run early enough that corrective actions can be completed and verified before the external auditor arrives, not just logged as open items.

Under OSHA's July 2000 self-audit policy, the agency will not routinely request self-audit reports at the start of an inspection or use them to identify hazards to focus on. That protection depends on correcting the hazards the audit identified.

First party means you audit yourself. Second party means a customer or other interested party audits you. Third party means an accredited independent body audits you and can issue a certificate.

The Practical Takeaway

Strip away the terminology and the internal audit vs external audit question comes down to one thing: who the audit is for. Yours is for you, and every authority that mandates an audit, from ISO 45001 to ANSI/ASSP Z10.0-2019 to OSHA's own VPP, mandates that one. Theirs is for someone else, and it should only ever confirm what you already knew. OSHA wrote down its position on self-audits a quarter of a century ago, which removes the last good excuse for not looking.

When was your last documented internal audit, and did anything actually get fixed afterward? Leave a comment with what your audit cycle looks like, and pass this to the person who owns your corrective action log.

Published by OSHA Workplace Safety

OSHA Workplace Safety Editorial Team

Published by OSHA Workplace Safety, a resource covering US workplace safety, OSHA compliance, ISO management standards, and ESG reporting. This guide is based on analysis of OSHA's published penalty schedule and Federal Register self-audit policy, the IIA's Global Internal Audit Standards and 2025 Pulse report, ANSI/ASSP Z10.0-2019, and ISO 45001, so employers get requirements as they are actually written.

Get Audit Ready Before the Auditor Arrives

New guides on OSHA compliance, ISO 45001 and safety management systems, sent as they publish.

Get Compliance Updates

Related Posts

OSHA 10 & 30Online Outreach training
Get Course Details

Request course details

Tell us what you need and we will come back with the course options, what the card covers and what it costs.

We reply within one business day. By sending this you agree to our privacy policy. We are not an OSHA-authorized provider — enquiries are passed to one.