Internal audit is not optional. ISO/IEC 42001:2023, the international standard for AI management systems, requires in Clause 9.2 that an organization audit its own AI management system at planned intervals, using auditors who are objective and impartial.

That internal check is a first-party audit and it is a fundamentally different thing from the third-party audit a certification body performs to grant your certificate. Between them sits a third kind, the second-party audit, run by a customer or partner.

Understanding which party is auditing, and why, is the difference between treating an audit as a box to tick and using it to build genuine assurance. The AI Governance Certification Institute (AIGCI) put this guide together to make the distinction clear.

A first-party audit is an internal audit an organization runs on its own AI management system; a third-party audit is an independent certification audit run by an accredited certification body. The two differ in who audits, under which rules and for what purpose.

The three parties behind every AIMS audit

An audit is defined the same way whoever performs it: a systematic, independent, documented process for gathering evidence and judging it against agreed criteria. What changes is the auditor's relationship to the organization. Conformity assessment recognises three parties and ANSI and ANAB describe them plainly: first-party, second-party, and third-party.

The first two are guided by ISO 19011, the standard for auditing management systems, while third-party certification is governed by ISO/IEC 17021-1.

The certification bodies that perform third-party audits are themselves accredited by bodies such as UKAS, with international recognition through the accreditation forum. Here is how the three compare as entities.

Party

Who audits

Guided by

Purpose

Certifies?

First-party

The organization itself

ISO 19011

Improve, prepare

No

Second-party

A customer or partner

ISO 19011

Supplier assurance

No

Third-party

An accredited certification body

ISO/IEC 17021-1

Independent proof

Yes

First-party vs third-party: what actually changes

The two ends of that spectrum are the ones people confuse most, so it is worth seeing them side by side. As you move from first to third party, one thing rises above all others: independence from the organization being audited.

Figure 1. The three parties of an AIMS audit, from internal to independent, with the first-party audit feeding the third.

Dimension

First-party (internal)

Third-party (certification)

Auditor

Your own people, or someone on your behalf

An external, accredited certification body

Independence

Impartial within the organization

Fully independent of the organization

Governing rules

ISO 19011 guidance

ISO/IEC 17021-1 requirements

Main purpose

Find and fix issues before it counts

Prove conformity to earn a certificate

Outcome

Internal findings and corrective actions

A certification decision

Required by the standard

Yes, Clause 9.2 of ISO 42001

No, but the route to certification

How the first-party audit feeds the third-party audit

These two are not rivals; they are sequential. The first-party audit is where an organization tests itself against ISO 42001 and its own rules, catches nonconformities, and fixes them while the stakes are low.

By the time an accredited body arrives for the third-party audit, the internal audit has already done the hard work of finding gaps. In fact the certification auditor will look for evidence that Clause 9.2 internal audits were carried out, so a strong internal audit programme is both preparation for certification and a requirement the certifier checks.

To build the internal capability, many organizations pursue the internal auditor certification, and to understand what the external assessment involves, our guide to the certification audit walks through its stages. In short, the first-party audit gets you ready; the third-party audit makes it official.

Which audit you need, and when

If your goal is to improve and to prepare for certification, you need a first-party audit, and under Clause 9.2 you are required to run one regardless. If a customer wants assurance about your AI practices, that is a second-party audit they will conduct on you. And when you want an independent, recognised certificate, only a third-party audit by an accredited body will do.

Most organizations experience all three over time, in that order of independence. Put simply: audit yourself first, satisfy your partners second, and let an accredited body certify you last.

Frequently asked questions

Is a first-party audit the same as an internal audit?

Yes. First-party audit is the formal name for an internal audit, one conducted by or on behalf of the organization on its own management system. ISO 42001 requires it under Clause 9.2.

Can a first-party audit certify my AI management system?

No. Certification can only come from a third-party audit by an accredited certification body. A first-party audit improves the system and prepares you, but it cannot grant a certificate.

What is a second-party audit?

It is an audit conducted by a party with an interest in your organization, typically a customer or partner assessing you as a supplier. It provides assurance to that party but does not lead to certification.

Do I have to do internal audits before certification?

Yes. Clause 9.2 of ISO 42001 requires internal audits at planned intervals, and a certification body will expect to see evidence that they were carried out before granting certification.

Who can perform a first-party audit?

Anyone competent and objective who is not responsible for the area being audited. The standard requires auditors to be impartial, so people cannot audit their own work, but they can be internal staff or external contractors acting on the organization's behalf.

Build the audit skills your AIMS needs

Whether you are running internal audits or preparing for certification, audit competence is what makes the difference. AIGCI's ISO 42001 auditor certifications develop both the internal-audit discipline behind a strong first-party programme and the rigour a third-party assessment demands. To see how the institute structures its programme, read more about the institute.