Key Takeaways
- An internal audit is performed by or on behalf of the organization itself to check that its own systems are working. An external audit is performed by an independent party outside the organization to give assurance to someone else.
- ANSI/ASSP Z10.0-2019 defines an audit as a systematic, independent, and documented process, and defines independence as not being responsible for the activity being audited.
- First party means you audit yourself; second party means a customer audits you; third party means an accredited independent body audits you and can issue a certificate.
- An OSHA inspection is enforcement with citations and penalties. An external audit is assurance, and the worst outcome is a major nonconformity and a suspended certificate.
- OSHA's published policy says the agency will not routinely request self-audit reports at the start of an inspection, and that protection is tied to correcting what the audit found.
- Internal Audit vs External Audit: The Short Answer
- What Is an Internal Audit?
- Who Runs It and Who They Report To
- What an Internal Audit Actually Looks For
- What Is an External Audit?
- Certification Bodies, Clients, and Regulators
- Stage 1, Stage 2, Surveillance, and Recertification
- 9 Key Differences Between Internal and External Audits
- What the Standards Actually Require
- First, Second, and Third Party Audits Explained
- An Audit Is Not an OSHA Inspection
- Enforcement vs Assurance
- What OSHA Can and Cannot Do With Your Audit Report
- How the Two Audits Work Together on a Real Safety Program
- A 12-Month Audit Calendar
- Who Is Allowed to Audit What
- Is an Internal Audit Required by Law?
- 7 Audit Mistakes That Turn a Minor Finding Into a Major One
- FAQ
- The Practical Takeaway
Plenty of US employers still avoid writing down what their own safety walkthroughs find, on the theory that a documented hazard is evidence waiting to be used against them. That fear is not imagined, and it is not new. OSHA published a formal policy in 2000 specifically because employers believed inspectors would treat self-audit reports as road maps to citations. Understanding the difference between an internal audit vs external audit, and between an audit and an inspection, is what settles that fear. This guide is built on OSHA's published penalty schedule and self-audit policy, the Institute of Internal Auditors' Global Internal Audit Standards, ANSI/ASSP Z10.0-2019, and the audit requirements written into ISO 45001.
Internal Audit vs External Audit: The Short Answer
An internal audit is performed by or on behalf of the organization itself to check that its own systems are working. An external audit is performed by an independent party outside the organization to give assurance to someone else, whether that is a certification body, a customer, or shareholders. Same techniques, completely different purpose and audience.
| Internal Audit | External Audit | |
|---|---|---|
| Performed by | Employees or a contractor acting for you | An independent outside party |
| Reports to | Audit committee, board, or top management | Certification body, client, or shareholders |
| Purpose | Improve the system | Provide assurance to others |
| Scope set by | The organization | A standard, contract, or law |
| Frequency | Continuous or on a rolling annual plan | Fixed cycle, often annual |
| Mandatory | Only where a standard or contract requires it | Usually yes, to keep a certificate or contract |
| Output | Findings and corrective actions | Formal opinion, certificate, or nonconformities |
| If it goes badly | Internal action plan | Lost certificate or lost contract |
What Is an Internal Audit?
An internal audit checks whether your management system does what your own documents say it does. It is a review you commission on yourself, and the findings belong to you.
ANSI/ASSP Z10.0-2019, the American national standard for occupational health and safety management systems, defines an audit as a systematic, independent, and documented process for gathering information and evaluating it objectively against defined criteria. Note the word documented. An undocumented walkthrough is not an audit under any recognized standard.
Who Runs It and Who They Report To
Internal auditors are usually employees, though smaller companies often hire an outside consultant to act as their internal auditor. Either way, the audit is done on the organization's behalf, which is what makes it internal.
Reporting lines are the part people get wrong. The Institute of Internal Auditors' Global Internal Audit Standards, which took effect on January 9, 2025, require the internal audit function to be positioned so it reports functionally to the board rather than to the managers whose work it examines. In a safety context, that means the person auditing the lockout program should not be reporting their findings only to the maintenance manager who owns it.
That positioning is being pushed further. In the IIA's 2025 North American Pulse of Internal Audit, surveyed between October and November 2024 with 85 percent of respondents based in the United States, 54 percent of chief audit executives described their function as almost fully or fully aligned with organizational strategy. Internal audit is moving from a checking function toward a strategic one, and safety audits are being pulled along with it.
What an Internal Audit Actually Looks For
Not paperwork. Objective evidence that the system works in practice:
- Whether the written procedure matches what people on the floor actually do
- Whether training records exist for everyone doing the task
- Whether previous findings were closed out or quietly forgotten
- Whether the controls listed in your risk assessment matrix are physically present and functioning
A good internal audit is uncomfortable. If yours never finds anything, it is not an audit, it is a formality.
What Is an External Audit?
An external audit is performed by someone with no stake in the result, for the benefit of a party outside your management chain.
Certification Bodies, Clients, and Regulators
Three very different groups run external audits, and they want different things:
- 1. Certification bodies audit your management system against a standard such as ISO 45001 and issue or withhold a certificate
- 2. Customers audit your site before awarding or renewing a contract, focused on whether you can deliver safely
- 3. Insurers and corporate parents audit to price risk or confirm group standards
A regulator like OSHA sits outside all three. More on why that distinction matters below.
Stage 1, Stage 2, Surveillance, and Recertification
Certification audits follow a defined cycle that catches most first-timers by surprise:
- 1. Stage 1 is a readiness review. The auditor checks your documentation, scope, and whether the system has been running long enough to produce records. Often done remotely.
- 2. Stage 2 is the full audit. Interviews, site observation, and evidence sampling across everything in scope.
- 3. Surveillance audits happen every six to twelve months and sample part of the system rather than all of it.
- 4. Recertification comes around at the three-year mark and looks at the whole system again.
The mechanics of getting through that first cycle are covered in more detail in the guide to how ISO certification works.
The nine differences that decide which audit you are actually facing.
9 Key Differences Between Internal and External Audits
- 1. Purpose. Internal audits exist to improve the system. External audits exist to prove something about it to an outside party.
- 2. Who performs it. Internal audits are done by or for the organization. External audits are done by a party with no interest in the outcome.
- 3. Independence. Under ANSI/ASSP Z10.0-2019, an internal auditor is independent of the activity being audited. An external auditor is independent of the entire organization, which is a much higher bar.
- 4. Who receives the report. Internal findings go to the audit committee, board or top management. External findings go to the certification body, the client, or the shareholders.
- 5. Who sets the scope. You choose what your internal audit covers. The standard, contract, or law dictates what the external audit covers.
- 6. Frequency. Internal audits run continuously on a rolling plan. External audits arrive on a fixed schedule you do not control.
- 7. Whether it is mandatory. Internal audits are required only where a standard or contract says so. External audits are the price of holding a certificate or a contract.
- 8. What it produces. Internal audits produce findings and corrective actions. External audits produce a formal opinion, a certificate decision, or graded nonconformities.
- 9. What failure costs. A bad internal audit costs you an action plan. A bad external audit can cost you the certificate, and with it, the customer who required it.
What the Standards Actually Require
Rather than argue about best practice, here is what four recognized authorities put in writing, and which type of audit each one is talking about.
| Authority | What it requires | Audit type |
|---|---|---|
| OSHA regulations | Specific written programs, records and training. No general requirement to audit the whole system | Neither, but inspections test the result |
| OSHA VPP | An annual self-evaluation of the safety and health management system, submitted to the Regional VPP Manager by February 15 each year | Internal, and OSHA states it is not a compliance audit |
| ISO 45001, clause 9.2 | Internal audits at planned intervals, with an audit program based on risk and the results of previous audits | Internal, verified by a third party |
| ANSI/ASSP Z10.0-2019 | Regular monitoring, internal audits, incident investigation and management review, with auditors free of bias and conflict of interest | Internal |
| IIA Global Internal Audit Standards | Internal audit positioned with functional reporting to the board, effective January 9, 2025 | Internal |
The pattern is worth noticing. Every authority that mandates an audit mandates the internal one. External audits are driven by certificates and contracts, not by regulators.
First, Second, and Third Party Audits Explained
The internal versus external split is useful shorthand, but auditors actually use a three-way model that is more precise:
- 1. First party audit. You audit yourself. This is the internal audit.
- 2. Second party audit. A party with a commercial interest audits you, typically a customer auditing a supplier before a contract renewal.
- 3. Third party audit. An accredited, independent body audits you against a standard and can issue a certificate. Nobody in the room has a commercial stake in the outcome.
The distinction matters commercially. A customer's second-party audit can be tough, but it cannot give you an ISO 45001 certificate. Only an accredited third party can, and only third party certificates are recognized on tender documents.
First, second, and third party audits, and who is standing on each side.
An Audit Is Not an OSHA Inspection
This is the confusion that keeps companies from auditing themselves at all, so it is worth being blunt about it.
Enforcement vs Assurance
An OSHA inspection is enforcement. It is usually unannounced, triggered by a complaint, a referral, a serious incident, or a programmed emphasis, and it can end in citations and monetary penalties. Per OSHA's published penalty schedule, a serious violation currently carries a maximum of $16,550, and a willful or repeat violation reaches $165,514. Failure to abate is charged per day past the abatement date.
An external audit is assurance. It is scheduled, you signed a contract for it, and the worst outcome is a major nonconformity and a suspended certificate. No fines, no citations. For what an actual enforcement visit involves, see the walkthrough of what to expect from an OSHA inspection.
What OSHA Can and Cannot Do With Your Audit Report
OSHA published its final policy on voluntary employer safety and health self-audits in the Federal Register on July 28, 2000, and it still stands. Under that policy, the agency will not routinely request self-audit reports at the start of an inspection, and will not use them as a means of identifying hazards to focus on during an inspection.
The policy also provides that where an employer identified a hazard through a voluntary self-audit and corrected it before an inspection, OSHA will not use the audit report as evidence of a willful violation.
Read the condition carefully, because it is the whole deal. The protection attaches to finding and fixing. An audit report full of open findings that nobody acted on is worse than no audit at all, because it documents that you knew.
The federal government runs a working example of exactly this model. Participants in OSHA's Voluntary Protection Programs are required to complete an annual self-evaluation of their safety and health management system and submit it to their OSHA Regional VPP Manager by February 15 each year. OSHA is explicit that this self-evaluation is not a compliance audit. It is a critical review of the program's effectiveness, written by the site itself, and sent to the regulator.
The protection in OSHA's policy attaches to the corrective action log, not the audit report.
How the Two Audits Work Together on a Real Safety Program
Internal and external audits are not rivals. The internal audit exists so that the external auditor never gets to be the first person who notices.
Sequence matters. Run the internal audit far enough ahead of the certification visit that corrective actions can actually be completed and verified, not just opened. Auditors can tell the difference between a closed action and a closed ticket.
A 12-Month Audit Calendar
A workable annual cycle for a mid-sized manufacturing site, built around the requirements in the table above:
- 1. Q1 internal audit of high-risk processes: confined space, hot work, lifting operations, energy isolation. VPP sites complete the annual self-evaluation before the February 15 submission date.
- 2. Q2 corrective actions verified and closed, then the surveillance audit from the certification body
- 3. Q3 internal audit of the remaining system elements, including contractor management and emergency preparedness
- 4. Q4 management review, next year's audit plan approved, objectives reset
High-risk processes get audited more often than once a year. Low-risk administrative elements can sit on an annual rotation. ISO 45001 clause 9.2 asks for exactly this: an audit program shaped by risk and by what previous audits found, which is what an HSE management system is designed to structure.
Who Is Allowed to Audit What
Two rules cause most of the friction, and both come straight from the standards:
- Nobody audits their own work. ANSI/ASSP Z10.0-2019 defines auditor independence as not being responsible for the activity under audit and being free of bias and conflict of interest. The safety manager who wrote the confined space procedure cannot be the person who audits it. In a small company, cross-audit between departments, or bring someone in.
- A consultant cannot build your system and then certify it. Accreditation rules prohibit a certification body from consulting on the same management system it certifies. Firms that offer to "get you certified" as a package are either subcontracting the audit or misrepresenting what they do.
An outside consultant acting as your internal auditor is perfectly legitimate. That is still a first party audit, because they are working on your behalf.
Is an Internal Audit Required by Law?
No general United States law requires a private employer to conduct a safety audit. OSHA requires specific programs, records, and training, but does not mandate a periodic audit of the whole system.
Three things change that answer in practice:
- 1. ISO 45001 clause 9.2 requires certified organizations to run internal audits at planned intervals. No internal audit means no certificate. The clause structure is covered in the breakdown of ISO 45001 requirements.
- 2. Voluntary programs with binding conditions. OSHA VPP participation carries the annual self-evaluation requirement described above, with a fixed submission deadline.
- 3. Contracts. Many large customers and general contractors require documented internal audits as a condition of doing business, and some state plans and specific standards carry their own review requirements.
7 Audit Mistakes That Turn a Minor Finding Into a Major One
- 1. Auditing the checklist instead of the risk. A generic template will confirm you have a procedure and never notice the procedure is wrong for your process.
- 2. Recording opinions instead of objective evidence. "Training appears adequate" is not a finding. "Three of eight operators had no record of energy isolation training" is.
- 3. Corrective actions that treat the symptom. Retraining one employee does not fix a procedure that nobody can follow.
- 4. The same person auditing their own area. It fails the independence definition in Z10.0-2019 and any external auditor will spot it immediately.
- 5. Findings that are opened and never closed. An aging open-findings list is the single fastest way to turn several minor nonconformities into one major one, and it removes the protection OSHA's self-audit policy offers.
- 6. Skipping management review. The audit feeds the review. Without it the loop never closes and nothing changes at the resourcing level.
- 7. Running the internal audit the week before the certification body arrives. There is no time to fix anything, and the auditor will notice the dates.
FAQ
Purpose and audience. An internal audit is run by or for the organization to improve its own systems. An external audit is run by an independent party to give assurance to someone outside the organization, such as a certification body or a customer.
The audit committee, the board, or top management, rather than the manager responsible for the area being audited. The IIA's Global Internal Audit Standards, effective January 9, 2025, require functional reporting to the board to protect independence.
The internal audit. It should run early enough that corrective actions can be completed and verified before the external auditor arrives, not just logged as open items.
Under OSHA's July 2000 self-audit policy, the agency will not routinely request self-audit reports at the start of an inspection or use them to identify hazards to focus on. That protection depends on correcting the hazards the audit identified.
First party means you audit yourself. Second party means a customer or other interested party audits you. Third party means an accredited independent body audits you and can issue a certificate.
The Practical Takeaway
Strip away the terminology and the internal audit vs external audit question comes down to one thing: who the audit is for. Yours is for you, and every authority that mandates an audit, from ISO 45001 to ANSI/ASSP Z10.0-2019 to OSHA's own VPP, mandates that one. Theirs is for someone else, and it should only ever confirm what you already knew. OSHA wrote down its position on self-audits a quarter of a century ago, which removes the last good excuse for not looking.
When was your last documented internal audit, and did anything actually get fixed afterward? Leave a comment with what your audit cycle looks like, and pass this to the person who owns your corrective action log.
New guides on OSHA compliance, ISO 45001 and safety management systems, sent as they publish.
Get Compliance Updates