Home → Guides → What is a compliance audit
Compliance guide

What is a compliance audit?

A compliance audit answers a simple but demanding question: do you actually meet your requirements — and can you prove it? Here is what an audit is, the main types, and where it differs from an inspection.

The definition

A compliance audit is a systematic, documented process for gathering objective evidence and evaluating it against a set of requirements — a standard, a regulation, an internal policy or a contract. Two words carry the weight: systematic (it follows a method, not a hunch) and documented (the evidence and the conclusion are recorded, so the result can be relied on later).

The purpose is not simply to be compliant, but to be able to demonstrate it — to a client, a regulator, a certification body or your own board.

The main types

First-party (internal) audit

You audit your own organisation against your own requirements or a standard. Internal audits find problems early, check that policies are actually followed, and prepare you for external scrutiny.

Second-party (supplier) audit

A customer or business partner audits you — or you audit a supplier — to check that contractual, quality or regulatory requirements are being met. Common in supply chains and contractor management.

Third-party (certification) audit

An independent certification or accreditation body audits you against a recognised standard (for example ISO 9001) to decide whether to certify. This is the audit that carries external credibility.

This first-/second-/third-party language is widely used and lines up with the ISO guidelines for auditing management systems (ISO 19011). For ISO management-system audits specifically, see the ISO internal audit checklist.

Audit, not inspection

An audit is not the same as an inspection. An inspection is a point-in-time check of physical conditions or a specific item; an audit is a broader, systematic evaluation of whether your processes are working. The audit vs inspection guide sets out the difference, and how to conduct a compliance audit walks through the process.

Run audits — and prove you fix what they find

Complys runs audits from templates, captures findings and non-conformances, turns each into an owned, dated corrective action tracked to verified closure, and keeps the full audit trail. General operational-compliance auditing — not a validated pharmaceutical or medical-device CAPA system.

Compliance audit software →

FAQs

What is a compliance audit?

A systematic, documented process for gathering evidence and evaluating it objectively to decide how far your organisation meets a set of requirements — a standard, a regulation, a policy or a contract. The point is not just to comply, but to be able to show you comply.

What are the types of audit?

Audits are commonly described as first-party (internal — you audit yourself), second-party (a customer or partner audits you, or you audit a supplier) and third-party (an independent certification body audits you against a standard). The terminology is widely used and aligns with the ISO auditing guidelines (ISO 19011).

Is a compliance audit a legal requirement?

Not universally. Some management-system standards and some contracts or regulators require audits; in other areas auditing is strong good practice rather than a specific legal duty. What is often expected is that you can evidence your compliance — which is exactly what an audit produces.

How is an audit different from an inspection?

An inspection is a point-in-time check of physical conditions or a specific item; an audit is a broader, systematic evaluation of whether your processes and management system are working. See the dedicated guide on audit vs inspection.

Related: how to conduct a compliance audit, compliance audit vs inspection, and compliance audit software. General information, not legal advice.