Audits and compliance
Third party audits, without three weeks of panic first
Audit preparation, internal audit programmes, findings and corrective action. Most audit pain is not caused by the auditor. It is caused by evidence that exists but cannot be found, and by a system that describes an organisation nobody recognises.
The problem
An audit announcement arrives and the organisation begins reconstructing its own history. Records are in three systems and two inboxes. The manual describes a process that changed a year ago. Last cycle’s findings were answered with a promise rather than a change, and the same finding comes back.
None of that is an auditing problem. It is a records and ownership problem that only becomes visible when somebody outside asks for proof.
What an auditor is actually doing
ISO 19011 gives guidance on auditing management systems, and is explicit that it provides guidance without itself leading to certification. An auditor works from scope and criteria to evidence, and then from evidence to a finding. That chain is the whole exercise.
Understanding it changes preparation completely. The question is not what will they ask. The question is which evidence would convince a reasonable stranger that what your manual claims is what actually happens.
What NorthSky does here
Audit work from both sides of the table, as a senior internal auditor and as someone whose own work has been audited.
- Pre-audit review: what an auditor will look for first and what your evidence currently supports.
- Building or tightening an internal audit programme that fits the size of the organisation.
- Findings and corrective action: root cause, effectiveness, and the follow-up that closes a finding for good.
- Documentation review, so the management system describes the organisation as it is today.
Who this is for
- Operators facing a first external audit who do not yet know what a finding is worth or how it is closed.
- Quality and safety managers with an audit programme on paper and no time to run it as intended.
- Organisations with repeat findings where the same issue returns because the corrective action addressed the symptom.
Articles in this area
There are no articles in this area yet. This hub is the entry point, and nothing is listed here that has not been written. The handbook on third party audits covers the full cycle in depth, and the how we work page explains what an advisory review looks like in practice.
Send the audit letter
Scope, criteria and date are usually enough to size the work. If the audit has already happened and the findings are the problem, send those instead.
Get in touchFrequently asked questions
How early should we start preparing for a third party audit?
Early enough that preparation is a review rather than a reconstruction. If evidence for the last twelve months can be produced within a day, you are ready. If it cannot, the work needed is records and ownership, and that work does not compress into the final week.
Can NorthSky audit us formally?
NorthSky provides advisory review, preparation and internal audit support. Certification and formal compliance verification are decisions for a certification body or the authority, and an advisory review does not substitute for either.
Do small organisations need a full management system?
They need one proportionate to what they do. The ICAO safety management framework is meant to be implemented commensurate with the size of the organisation and the complexity of its services, and an oversized system is a genuine risk in itself because nobody maintains it.
