Internal audit is not optional. ISO/IEC 42001:2023, the international standard for AI management systems, requires in Clause 9.2 that an organization audit its own AI management system at planned intervals, using auditors who are objective and impartial.
That internal check is a first-party audit and it is a fundamentally different thing from the third-party audit a certification body performs to grant your certificate. Between them sits a third kind, the second-party audit, run by a customer or partner.
Understanding which party is auditing, and why, is the difference between treating an audit as a box to tick and using it to build genuine assurance. The AI Governance Certification Institute (AIGCI) put this guide together to make the distinction clear.
A first-party audit is an internal audit an organization runs on its own AI management system; a third-party audit is an independent certification audit run by an accredited certification body. The two differ in who audits, under which rules and for what purpose.
The three parties behind every AIMS audit
An audit is defined the same way whoever performs it: a systematic, independent, documented process for gathering evidence and judging it against agreed criteria. What changes is the auditor's relationship to the organization. Conformity assessment recognises three parties and ANSI and ANAB describe them plainly: first-party, second-party, and third-party.
The first two are guided by ISO 19011, the standard for auditing management systems, while third-party certification is governed by ISO/IEC 17021-1.
The certification bodies that perform third-party audits are themselves accredited by bodies such as UKAS, with international recognition through the accreditation forum. Here is how the three compare as entities.
|
Party |
Who audits |
Guided by |
Purpose |
Certifies? |
|---|---|---|---|---|
|
First-party |
The organization itself |
ISO 19011 |
Improve, prepare |
No |
|
Second-party |
A customer or partner |
ISO 19011 |
Supplier assurance |
No |
|
Third-party |
An accredited certification body |
ISO/IEC 17021-1 |
Independent proof |
Yes |
First-party vs third-party: what actually changes
The two ends of that spectrum are the ones people confuse most, so it is worth seeing them side by side. As you move from first to third party, one thing rises above all others: independence from the organization being audited.

Figure 1. The three parties of an AIMS audit, from internal to independent, with the first-party audit feeding the third.
|
Dimension |
First-party (internal) |
Third-party (certification) |
|---|---|---|
|
Auditor |
Your own people, or someone on your behalf |
An external, accredited certification body |
|
Independence |
Impartial within the organization |
Fully independent of the organization |
|
Governing rules |
ISO 19011 guidance |
ISO/IEC 17021-1 requirements |
|
Main purpose |
Find and fix issues before it counts |
Prove conformity to earn a certificate |
|
Outcome |
Internal findings and corrective actions |
A certification decision |
|
Required by the standard |
Yes, Clause 9.2 of ISO 42001 |
No, but the route to certification |
How the first-party audit feeds the third-party audit
These two are not rivals; they are sequential. The first-party audit is where an organization tests itself against ISO 42001 and its own rules, catches nonconformities, and fixes them while the stakes are low.
By the time an accredited body arrives for the third-party audit, the internal audit has already done the hard work of finding gaps. In fact the certification auditor will look for evidence that Clause 9.2 internal audits were carried out, so a strong internal audit programme is both preparation for certification and a requirement the certifier checks.
To build the internal capability, many organizations pursue the internal auditor certification, and to understand what the external assessment involves, our guide to the certification audit walks through its stages. In short, the first-party audit gets you ready; the third-party audit makes it official.
Which audit you need, and when
If your goal is to improve and to prepare for certification, you need a first-party audit, and under Clause 9.2 you are required to run one regardless. If a customer wants assurance about your AI practices, that is a second-party audit they will conduct on you. And when you want an independent, recognised certificate, only a third-party audit by an accredited body will do.
Most organizations experience all three over time, in that order of independence. Put simply: audit yourself first, satisfy your partners second, and let an accredited body certify you last.
Frequently asked questions
Is a first-party audit the same as an internal audit?
Yes. First-party audit is the formal name for an internal audit, one conducted by or on behalf of the organization on its own management system. ISO 42001 requires it under Clause 9.2.
Can a first-party audit certify my AI management system?
No. Certification can only come from a third-party audit by an accredited certification body. A first-party audit improves the system and prepares you, but it cannot grant a certificate.
What is a second-party audit?
It is an audit conducted by a party with an interest in your organization, typically a customer or partner assessing you as a supplier. It provides assurance to that party but does not lead to certification.
Do I have to do internal audits before certification?
Yes. Clause 9.2 of ISO 42001 requires internal audits at planned intervals, and a certification body will expect to see evidence that they were carried out before granting certification.
Who can perform a first-party audit?
Anyone competent and objective who is not responsible for the area being audited. The standard requires auditors to be impartial, so people cannot audit their own work, but they can be internal staff or external contractors acting on the organization's behalf.
Build the audit skills your AIMS needs
Whether you are running internal audits or preparing for certification, audit competence is what makes the difference. AIGCI's ISO 42001 auditor certifications develop both the internal-audit discipline behind a strong first-party programme and the rigour a third-party assessment demands. To see how the institute structures its programme, read more about the institute.