The auditor’s craft
Lesson 1 of 5 in Lead Auditor Track: Auditing an AIMS with ISO 19011 Discipline.
Everything so far in this domain taught you to survive an audit. This module flips the chair: you are now the person planning the audit, asking the questions, grading the findings, and defending every word of the report. Auditing is a craft with its own discipline, its own standard — ISO 19011, the guidelines for auditing management systems — and its own professional identity.
Start with an honesty check the market routinely fails. A ‘Lead Auditor’ credential is a personnel certification: it attests that you, an individual, have demonstrated knowledge of the audit method and (usually) the target standard, typically via a multi-day course and exam from a training and personnel-certification body such as PECB or an Exemplar-Global-certified provider. ISO itself certifies nobody — not organisations, and not people. The credential says you know how to audit; it does not by itself authorise you to issue certificates. That authority comes only from working for an accredited certification body, inside the 17021-1/42006 chain you mapped in the previous module — the CB’s accreditation, not your certificate, is what makes a third-party audit’s conclusions carry weight.
ISO 19011 opens with seven principles of auditing, and they are not decoration — every hard call you will make in this module resolves back to one of them. When an auditee disputes a finding, when a client pressures you to soften a report, when you are tempted to tell the auditee how to fix things: the principles are the tie-breaker.
Integrity — the foundation of professionalism
Perform work honestly, diligently, and responsibly; observe legal requirements; stay impartial and resist influence. The blunt version: an audit bought is an audit worthless. Every other principle collapses if this one does.
Fair presentation — report truthfully and accurately
Findings, conclusions, and reports reflect the audit activities truthfully and completely — including unresolved disagreements and obstacles encountered. Omitting the awkward finding because the client relationship is valuable is the most common real-world breach of this principle.
Due professional care — diligence and judgement
Apply the care the importance of the task warrants, and exercise reasoned judgement in every audit situation. For AIMS audits this includes knowing the limits of your own AI competence — and saying so when the engagement needs a technical expert.
Confidentiality — security of information
You will read risk registers, incident records, and model documentation the auditee shows no one else. Protect it, use it only for audit purposes, and never trade on it — during the engagement or after it.
Independence — the basis for impartiality
Be independent of the activity audited wherever practicable, and free of bias and conflict of interest always. Internal auditors cannot always be organisationally independent — but they must not audit their own work. Third-party auditors must be independent, full stop.
Evidence-based approach — reproducible conclusions
Audit evidence is verifiable: records, statements, observations. Because audits sample rather than exhaust, conclusions carry sampling uncertainty — which is exactly why every conclusion must trace to evidence someone else could re-examine and reach the same result.
Risk-based approach — effort follows risk
Added in the 2018 revision: point audit effort at the matters that are significant to the auditee and to the audit objectives. In an AIMS, that means the credit-scoring model in production gets more sample than the internal lunch-menu chatbot.
The same method serves three very different masters. A first-party audit is the organisation auditing itself — the clause 9.2 internal audit you met inside 42001. A second-party audit is one organisation auditing another it has a stake in — a bank auditing its GPAI vendor’s AIMS before renewal. A third-party audit is an independent body auditing for certification or regulatory purposes. ISO 19011 gives guidance for all three; third-party certification auditing additionally answers to 17021-1 and, for AIMS, 42006 — the rules of the accreditation chain covered in the previous module. Know which chair you sit in before you open your notebook: it changes who your client is, what independence means, and what your findings can be used for.
| First-party (internal) | Second-party (supplier/customer) | Third-party (certification) | |
|---|---|---|---|
Who audits whom | The organisation audits itself (own staff or hired-in auditors acting internally) | A customer — or someone on its behalf — audits a supplier or partner | An independent certification body audits the organisation |
Audit client | The organisation’s own management | The customer commissioning the audit | The auditee organisation (contractually) — but the CB’s duty runs to the integrity of the certificate |
Independence bar | Auditors must not audit their own work; full organisational independence often impracticable | Inherently external to the auditee, but commercially interested — the customer wants leverage | Highest: full independence plus 17021-1 impartiality machinery (no consulting, decision separation) |
Governing documents | ISO 19011 + 42001 clause 9.2 | ISO 19011 + the contract’s audit clause | ISO/IEC 17021-1 + ISO/IEC 42006, with 19011 as the method beneath |
What the output can claim | Input to management review and improvement — no external assurance value | Contractual leverage: renewal, remediation demands, exit | An accredited certificate the market and regulators can rely on |
AIMS example | Your governance team samples A.6 lifecycle records before Stage 2 | A hospital audits its clinical-AI vendor’s impact-assessment process under an A.10-driven contract clause | A CB’s team conducts Stage 2 and recommends certification |
Key terms: iso 19011, lead auditor, first party audit, second party audit, third party audit, audit evidence
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.