Examples
Worked examples
- Is an instance
A clinical diagnostics lab audits a reagent manufacturer against its own supplier-qualification specification before adding it to the approved-vendor list.
- Is an instance
A clinical trial sponsor audits a contracted CRO's SOPs and training records against the sponsor's own clinical quality agreement.
Counter-examples
Looks similar, but isn't
- Not an instance
A lab's internal quality manager reviewing the lab's own compliance with its documented procedures is a first-party (internal) audit, not second-party — no external supplier relationship is involved.
- Not an instance
An accredited certification body auditing a lab against ISO/IEC 17025 to grant or renew accreditation is a third-party audit — the body has no buyer-supplier relationship with the lab.
Editorial commentary
A second-party audit is an audit that an organization conducts, or arranges to have conducted on its behalf, against one of its own suppliers, contractors, or other external providers — assessing that supplier against requirements the auditing organization itself has specified (a purchase contract, a quality agreement, a specification, or a relevant standard such as ISO 9001 or ISO 13485). The defining feature is the relationship: the auditor represents the customer’s interest, not an independent third party’s, and the result is used by that customer to decide whether to qualify, continue, or disqualify the supplier — not to grant the supplier a certification usable with other customers.
Where it sits in the first/second/third-party audit framework
Quality-management practice (reflected in ISO 9000 and the ISO 19011 auditing guidance that most laboratory and medical-device quality systems reference) sorts audits into three categories by who the auditor works for relative to the audited organization:
- First-party audit — an organization audits itself (an internal audit against its own quality management system, e.g. an ISO 9001 or ISO 13485 internal audit program, or a laboratory’s own internal review against ISO/IEC 17025).
- Second-party audit — an organization (the customer) audits an external party it has, or is considering, a commercial relationship with (a supplier, contract manufacturer, contract research organization, reagent or equipment vendor, or outsourced testing laboratory).
- Third-party audit — an independent body with no commercial stake in the outcome audits an organization, typically to issue or maintain a certification (e.g. an accredited certification body auditing against ISO 9001, ISO 13485, or ISO/IEC 17025) or to fulfil a regulatory inspection role (e.g. an FDA facility inspection).
The three categories are distinguished purely by the auditor-auditee relationship, not by audit rigor, scope, or method — a second-party audit can be as thorough as a third-party certification audit; it simply produces a finding the customer keeps for its own supplier-qualification file rather than a portable certificate.
What makes something a second-party audit
An audit qualifies as second-party when three conditions hold:
- A commercial or contractual relationship exists (or is being evaluated) between the auditing organization and the audited party — a live supplier, a prospective supplier under qualification, or an outsourced service provider such as a contract testing lab or contract manufacturer.
- The auditing organization sets, or adopts as its own, the audit criteria — a purchase specification, a quality/technical agreement, a master service agreement’s quality clauses, or a named standard the customer requires the supplier to meet.
- The result is used internally by the auditing organization — to approve, conditionally approve, place on a corrective-action watch, or remove the supplier from an approved-supplier list — rather than issued as a certificate the supplier can present to other customers.
The audit does not have to be performed in person by the customer’s own staff to count as second-party: many organizations contract a third-party auditing firm to physically conduct the visit, but as long as that auditor is working on the customer’s behalf, against the customer’s criteria, for the customer’s internal decision, the audit remains second-party in character — the commissioning relationship determines the category, not who physically holds the checklist.
Worked examples
Example 1 — reagent supplier qualification. A clinical diagnostics laboratory sends its own quality staff to audit a reagent manufacturer before adding that manufacturer to its approved-vendor list. The audit checks the manufacturer’s change-control process, lot-release testing, and storage/shipping controls against the laboratory’s own supplier-qualification specification. This is a textbook second-party audit: the lab is the customer, sets its own criteria, and the outcome (approve/reject/conditional) stays internal to the lab’s vendor file.
Example 2 — sponsor audit of a contract research organization (CRO). A clinical trial sponsor audits a CRO it has contracted to run trial monitoring and data management, checking the CRO’s standard operating procedures and staff training records against the sponsor’s clinical quality agreement and applicable Good Clinical Practice expectations. Because the sponsor is the CRO’s customer and the audit criteria come from the sponsor’s own contract, this is second-party even though it closely resembles a regulatory GCP inspection in method.
Counter-example
A laboratory’s own internal quality manager reviewing that same laboratory’s compliance with its documented procedures is a first-party (internal) audit, not second-party — there is no external supplier relationship involved. Conversely, an accredited certification body auditing that laboratory against ISO/IEC 17025 to decide whether to grant or renew the lab’s accreditation is a third-party audit — the certification body has no commercial buyer-supplier relationship with the lab and the resulting certificate is meant to be relied on by parties other than the auditor itself.
Why the distinction matters for procurement and supply-chain compliance
Second-party audits are the mechanism by which a purchasing organization gets direct, first-hand assurance about a specific supplier’s quality system, rather than relying solely on that supplier’s existing third-party certificates. Certificates (e.g. an ISO 9001 or ISO 13485 certificate) confirm a supplier’s quality management system meets a general standard, but they don’t confirm the supplier can reliably meet a particular customer’s specific technical requirements, capacity needs, or contractual quality clauses — that gap is exactly what a second-party audit is designed to close, and why many supplier-qualification and approved-vendor-list programs in laboratory and clinical-research procurement require one before onboarding a new critical supplier, alongside — not instead of — reviewing the supplier’s third-party certifications.
Related terms
- First-party audit (internal audit)
- Third-party audit / certification audit
- Supplier qualification
- Approved supplier list / approved vendor list
- Corrective and Preventive Action (CAPA)
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="Second-Party Audit"
vocab-term-identifier="https://casrai.org/dictionary/term/second-party-audit" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/second-party-audit",
"name": "Second-Party Audit",
"identifier": "https://casrai.org/dictionary/term/second-party-audit",
"description": "A second-party audit is an audit an organization conducts, or commissions, against one of its own suppliers, contractors, or external providers — using the customer's own criteria (a contract, quality agreement, or specification) — to decide whether to qualify, continue, or remove that supplier, as distinct from a first-party (internal self-audit) or a third-party (independent certification/regulatory) audit.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
"url": "https://casrai.org/dictionary/term/second-party-audit",
"sameAs": [],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"dateModified": "2026-08-12T15:04:45",
"inLanguage": "en"
}






