The auditor’s craft

Lesson 1 of 5 in Lead Auditor Track: Auditing an AIMS with ISO 19011 Discipline.

Everything so far in this domain taught you to survive an audit. This module flips the chair: you are now the person planning the audit, asking the questions, grading the findings, and defending every word of the report. Auditing is a craft with its own discipline, its own standard — ISO 19011, the guidelines for auditing management systems — and its own professional identity.

Start with an honesty check the market routinely fails. A ‘Lead Auditor’ credential is a personnel certification: it attests that you, an individual, have demonstrated knowledge of the audit method and (usually) the target standard, typically via a multi-day course and exam from a training and personnel-certification body such as PECB or an Exemplar-Global-certified provider. ISO itself certifies nobody — not organisations, and not people. The credential says you know how to audit; it does not by itself authorise you to issue certificates. That authority comes only from working for an accredited certification body, inside the 17021-1/42006 chain you mapped in the previous module — the CB’s accreditation, not your certificate, is what makes a third-party audit’s conclusions carry weight.

ISO 19011 opens with seven principles of auditing, and they are not decoration — every hard call you will make in this module resolves back to one of them. When an auditee disputes a finding, when a client pressures you to soften a report, when you are tempted to tell the auditee how to fix things: the principles are the tie-breaker.

Integrity — the foundation of professionalism

Perform work honestly, diligently, and responsibly; observe legal requirements; stay impartial and resist influence. The blunt version: an audit bought is an audit worthless. Every other principle collapses if this one does.

Fair presentation — report truthfully and accurately

Findings, conclusions, and reports reflect the audit activities truthfully and completely — including unresolved disagreements and obstacles encountered. Omitting the awkward finding because the client relationship is valuable is the most common real-world breach of this principle.

Due professional care — diligence and judgement

Apply the care the importance of the task warrants, and exercise reasoned judgement in every audit situation. For AIMS audits this includes knowing the limits of your own AI competence — and saying so when the engagement needs a technical expert.

Confidentiality — security of information

You will read risk registers, incident records, and model documentation the auditee shows no one else. Protect it, use it only for audit purposes, and never trade on it — during the engagement or after it.

Independence — the basis for impartiality

Be independent of the activity audited wherever practicable, and free of bias and conflict of interest always. Internal auditors cannot always be organisationally independent — but they must not audit their own work. Third-party auditors must be independent, full stop.

Evidence-based approach — reproducible conclusions

Audit evidence is verifiable: records, statements, observations. Because audits sample rather than exhaust, conclusions carry sampling uncertainty — which is exactly why every conclusion must trace to evidence someone else could re-examine and reach the same result.

Risk-based approach — effort follows risk

Added in the 2018 revision: point audit effort at the matters that are significant to the auditee and to the audit objectives. In an AIMS, that means the credit-scoring model in production gets more sample than the internal lunch-menu chatbot.

The same method serves three very different masters. A first-party audit is the organisation auditing itself — the clause 9.2 internal audit you met inside 42001. A second-party audit is one organisation auditing another it has a stake in — a bank auditing its GPAI vendor’s AIMS before renewal. A third-party audit is an independent body auditing for certification or regulatory purposes. ISO 19011 gives guidance for all three; third-party certification auditing additionally answers to 17021-1 and, for AIMS, 42006 — the rules of the accreditation chain covered in the previous module. Know which chair you sit in before you open your notebook: it changes who your client is, what independence means, and what your findings can be used for.

Three audit types, one method
First-party (internal)Second-party (supplier/customer)Third-party (certification)

Who audits whom

The organisation audits itself (own staff or hired-in auditors acting internally)

A customer — or someone on its behalf — audits a supplier or partner

An independent certification body audits the organisation

Audit client

The organisation’s own management

The customer commissioning the audit

The auditee organisation (contractually) — but the CB’s duty runs to the integrity of the certificate

Independence bar

Auditors must not audit their own work; full organisational independence often impracticable

Inherently external to the auditee, but commercially interested — the customer wants leverage

Highest: full independence plus 17021-1 impartiality machinery (no consulting, decision separation)

Governing documents

ISO 19011 + 42001 clause 9.2

ISO 19011 + the contract’s audit clause

ISO/IEC 17021-1 + ISO/IEC 42006, with 19011 as the method beneath

What the output can claim

Input to management review and improvement — no external assurance value

Contractual leverage: renewal, remediation demands, exit

An accredited certificate the market and regulators can rely on

AIMS example

Your governance team samples A.6 lifecycle records before Stage 2

A hospital audits its clinical-AI vendor’s impact-assessment process under an A.10-driven contract clause

A CB’s team conducts Stage 2 and recommends certification

Key terms: iso 19011, lead auditor, first party audit, second party audit, third party audit, audit evidence

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.