Find out whether the system is actually working
Internal, supplier, independent and contract auditing that tells you whether the system you built is being used, and whether it is holding.
A system tells you how work is meant to happen. An audit tells you whether it does.
Without the second, the first is a hypothesis.
The gap opens quietly. A process gets written, it is followed for a while, then a project runs tight, someone takes a shortcut that works, and the shortcut becomes the method. Nothing was decided. The system simply stopped describing reality, and nobody noticed because nobody was looking.
Four audits, four different reasons
Internal quality auditing. Why: ISO 9001 clause 9.2 requires it, and you need to know whether your own system is being followed. What you get: a programme aimed at your delivery risk rather than at what is easy to audit, following ISO 19011, findings written in your language with a cause rather than a clause number, and an end to the same finding reappearing every year.
Supplier and second party auditing. Why: if you carry head contractor obligations, your supplier’s quality failure arrives as your quality failure, usually late and usually expensive. What you get: what a supplier actually does, rather than what they claimed on the prequalification form. It matters most where a subconsultant’s work goes out under your name, or a subcontractor’s records become your evidence of compliance.
Independent auditing. Why: a board, a client or a funder needs a view that is not the delivery team’s own account of itself. What you get: an informed answer to a specific question. Is this project run the way we think it is. Is this supplier meeting its obligations. Is this system doing what it was built to do. This is assurance, not certification, and it produces no certificate.
Contract auditing on infrastructure projects. Why: NZS 3910 and NZS 3916 set quality obligations at a level of generality that leaves considerable room, so a requirement for a quality plan or an inspection and test plan produces whatever the contractor understood you to mean. What you get: conformance checked against what the contract actually requires, including hold and witness point discipline, and whether the documentation being produced will be usable by the people who inherit the asset.
What you end up with
- A clear answer on whether your system is being followed, rather than an assumption
- Findings written so someone can act on them, with a cause rather than a clause reference
- An audit programme your own team can run once we have set it up and briefed them
- Contractor and supplier conformance you can evidence rather than assert
- Audit evidence that satisfies a certification body without a scramble beforehand
Also in Quality Management
Common questions
Can you certify us?
No, and nobody who builds your system can. Certification comes from an accredited body that must be independent of whoever designed what is being certified. That independence is the entire value of the certificate. We prepare you for it and support you through it.
What is the difference between independent auditing and certification?
A certification audit tests conformance to a standard and produces a certificate. An independent audit answers whatever question you actually have, which is usually closer to whether a supplier is doing what they said. No certificate, often a more useful answer.
Our internal audits keep finding nothing. Is that good?
Usually not. A programme that consistently finds nothing is normally looking in low risk places, being run by someone auditing their own work, or asking whether documents exist rather than whether the process is followed.
Do you audit our subcontractors?
Yes. Second party auditing is a substantial part of this work, particularly for firms carrying head contractor obligations.