Book
The Power of third party audits
A working handbook on buying and running an external audit: how to decide what you actually need audited, how to choose an auditor who will tell you something you do not already know, and how to handle the findings once they land on your desk. Written in English for anyone who has been told to arrange an independent audit and has no template to follow. The author is an air traffic controller and senior internal auditor with over twenty years in operational aviation.
What the book covers
What a third-party audit is and how it differs from a first-party internal audit or a second-party customer audit. The main audit types and what each one is good for. How to write a scope that produces useful findings instead of a clean report. What to look for when selecting and comparing auditors, what a proposal should contain, and how to read a quotation. How to prepare an organisation so the audit week is not wasted on document retrieval. What to do with findings, and how to close them without turning corrective action into paperwork.
Who it is for
Quality and safety managers arranging an external audit for the first time. Accountable managers who have to sign the contract and want to know what they are buying. Operations managers in small organisations where the person commissioning the audit is also the person being audited. It is equally useful to anyone who has run audits for years and suspects they have been buying the wrong scope out of habit.
What it is not
It is not a standard, and it is not a substitute for one. It does not reproduce the requirements of any management system standard, and reading it will not by itself satisfy any requirement placed on your organisation. It is also not a guide to becoming an auditor: it is written from the perspective of the organisation paying for the audit, not the body delivering it.
The problem the book addresses
Most organisations commission their first external audit under pressure. A customer has asked for evidence, a regulator has raised a finding, a contract has a clause in it, or a board has decided that independent assurance would be prudent. The decision to buy an audit gets made quickly, and the harder question, what exactly should be audited and to what criteria, gets settled by whichever auditor answers the phone first.
The result is predictable. The scope is copied from the auditor’s standard template, the audit examines what that template examines, and the report confirms what the organisation already believed. Nobody has done anything wrong and nobody has learned anything either. The money is spent, the certificate or report is filed, and the same weaknesses are still there the following year.
This handbook is about the decisions taken before an auditor arrives, because those decisions determine almost everything about the value of the audit. An audit is a purchased service, and like any purchased service it rewards a buyer who knows what good looks like.
First, second and third party, and why the distinction matters commercially
Auditing is conventionally split three ways. A first-party audit is an organisation auditing itself. A second-party audit is a customer auditing a supplier. A third-party audit is conducted by a body independent of both. The general principles, audit programme management, and auditor competence expectations behind all three are set out in ISO 19011, which is guidance rather than a requirement, and the requirements applying specifically to bodies that audit and certify management systems sit in ISO/IEC 17021-1.
The distinction is not academic, because it determines what the output is worth to somebody outside your organisation. An internal audit is evidence that you looked. A third-party audit is evidence that somebody with nothing to gain looked. When a customer, an insurer or an authority asks for assurance, they are usually asking for the second kind, and the book is explicit about when the cheaper option is genuinely sufficient and when it is not.
It also covers the layer above the auditor. Certification bodies are themselves assessed, and the international recognition arrangements maintained by the IAF exist so that a certificate issued in one country carries meaning in another. Understanding that structure is what lets a buyer tell a meaningful certificate from a decorative one.
Choosing an auditor, and the questions that separate them
Auditor selection is where most of the avoidable cost sits. Proposals are difficult to compare because they describe effort rather than outcome, and the cheapest quotation is frequently the one scoped to find the least. The book works through what to ask: how audit days are calculated and what happens if the estimate is wrong, who will actually be in the room as opposed to whose profile appears in the proposal, what sector experience the audit team has, how findings are graded, and what the process is when you disagree with one.
There is a chapter on the awkward questions too. Independence is easy to claim and harder to demonstrate, particularly when the same firm offers consulting alongside auditing. The book sets out how to ask about that without insulting anyone, and why an auditor who has already helped you build the system cannot credibly assess it.
Managing the audit, and managing what comes out of it
The second half of the handbook is operational. It covers what to send in advance and what to hold back, how to brief staff so they answer honestly rather than defensively, why the opening meeting matters more than people expect, and how to run the audit week without half the organisation stopping work.
Findings get the most attention, because that is where value is either captured or lost. A finding is information the organisation paid for, and the common failure is to treat it as an accusation and close it with the smallest change that satisfies the auditor. The book distinguishes correcting an instance from correcting the cause, explains why root cause analysis so often stops one step too early, and gives a practical way to decide which findings deserve a real change of process and which genuinely are one-off slips.
If you want to see how NorthSky approaches this in practice before or after reading, the how we work page sets out the method, and you can outline a specific situation on the contact page.
Editions and format
The book is available as a paperback and as a Kindle print replica. The content is identical. The print replica keeps the paperback page layout, which means text does not reflow to fit a small screen, so it reads best on a tablet or a computer rather than on a phone. If you expect to work through the checklists alongside colleagues, the paperback is the more practical of the two.
Edition details
| Format | Pages | Published | ISBN-13 or ASIN | Amazon |
|---|---|---|---|---|
| Kindle | 125 | March 26, 2024 | B0CWBKZB87 | View on AmazonThis is a print replica, so it keeps the paperback layout and reflows less well on small screens. Page count differs from the paperback because the replica preserves the original page geometry. |
| Paperback | 85 | March 24, 2024 | 979-8320811338 | View on AmazonSet more tightly than the Kindle print replica, which is why the page count is lower for identical content. |
Arranging an audit, or trying to make sense of one you already have?
A handbook can explain how the process works. It cannot look at your situation and tell you whether the scope in front of you is the right one.
NorthSky advises on audit scoping, preparation, and the handling of findings in aviation and UAS organisations. If you have a proposal on your desk, a set of findings you are unsure how to close, or a customer requirement you do not yet know how to meet, describe the situation and we will start with a short conversation at no cost.
Common questions
Is this book about aviation only?
No. The audit process it describes is generic and applies to any management system audit, and the chapters on scoping, selection, and findings are industry-neutral. The examples lean on aviation because that is where the author's experience is, and readers from aviation and UAS organisations will recognise more of the context, but the material is not restricted to that sector.
Does it explain how to get certified to a specific standard?
No, and deliberately so. Certification requirements belong to the standard itself and to the certification body, and any handbook that summarised them would be out of date before long. This book covers the part nobody publishes: how to buy the audit, how to run it, and what to do afterwards.
Can I use the book as evidence in an audit or to a regulator?
No. It is professional literature and says nothing about your organisation. Evidence of conformity has to be your own procedures, your own records, and your own demonstrated practice. The book can help you write those better, but it does not itself demonstrate anything about you.
I already run internal audits. Is there anything here for me?
Yes, though a different part of it. The chapters on audit types and on independence explain where an internal programme reaches its limit and what an external audit adds that yours structurally cannot. The sections on scoping and on findings apply to internal audits with very little translation.
What is the difference between the Kindle edition and the paperback?
The content is the same. The Kindle edition is a print replica, so it preserves the paperback layout rather than reflowing text, and it reads better on a larger screen than on a phone. Page counts differ, 125 for the replica against 85 for the paperback, purely because of how each is set.
Is there a Norwegian edition?
Not at present. This book is published in English only. There is a Norwegian-language page on this site describing the book for Norwegian readers, but the book itself has not been translated.
How long is it, and how is it meant to be read?
It is short on purpose. It is structured to be used in the order the work happens, so you can read the scoping chapters while deciding what to buy and return to the findings chapters months later when the report arrives, rather than reading it end to end in one sitting.
Scope of NorthSky’s work
NorthSky provides operational risk decision support and advisory guidance. Outputs do not constitute regulatory certification, aerodrome licensing, compliance verification, or formal authority determinations.
Sources
- Amazon, Kindle print replica edition of The Power of third party audits, ASIN B0CWBKZB87
- Amazon, paperback edition of The Power of third party audits, ASIN B0D11R2VDJ
- Amazon Author Central, Roe Nerem
- ISO 19011:2018, Guidelines for auditing management systems
- ISO/IEC 17021-1:2015, Conformity assessment, Requirements for bodies providing audit and certification of management systems
- ISO, Conformity assessment
- IAF, About the IAF MLA
