Management system audits are an integral part of an organization's management and governance.
Whether they are called "internal audits", "external audits", "first party audits", "second party audits" or "third party audits", they enable management, at the highest level, to obtain essential information on the "state of health" of the various management systems in place within the organization.
Carrying out management system audits requires the involvement of a number of stakeholders: an audit team (audit manager and auditors), auditees, as well as technical experts, observers, guides, etc.
Each of these stakeholders has a well-defined role, and certain limits must not be overstepped if the exercise is to remain worthwhile.
A management system audit has its limits, and it is important to determine where these lie so as not to exceed them.
It's important to remember that implementing a management system is a voluntary process, and as such, it's important not to turn a management system audit into an inquisition, or at the very least, a courtesy visit.
The exercise is therefore not a simple one, and its practice requires the appropriation of basic tools that the players involved need to know.
Management system audits are constantly evolving, due to the multiplicity of management system standards and cultural and technological changes.
Note :
A glossary of important terms and expressions used in the article, plus a table of acronyms, notations and symbols, is provided at the end of the article.