Sustainability Language

Audit

A systematic, independent and documented process for obtaining objective evidence and evaluating it against defined criteria to determine the extent to which requirements are fulfilled.

Established · Version master-draft-2026-08-10

Expert review openNo editor-accepted expert review yet

Definition

A systematic, independent and documented process for obtaining objective evidence and evaluating it against defined criteria to determine the extent to which requirements are fulfilled.

Overview

“An audit is not a search for reassurance; it is a disciplined test of whether evidence meets a requirement. ”

Audit is one of the most familiar words in assurance and one of the easiest to overstate. Organisations speak of audited suppliers, audited farms and audited data as though the word itself guarantees safety, legality or responsible performance. It does not. An audit is a method for examining defined evidence against defined criteria within a defined scope and period.

ISO 19011:2026 describes audit as a systematic, independent and documented process for obtaining objective evidence and evaluating it objectively to determine the extent to which audit criteria are fulfilled. The definition matters because each element limits the claim. Systematic means planned rather than improvised. Independent means judgement is sufficiently free from the activity being examined.

Documented means the method and conclusion can be followed. Criteria establish the requirement. Evidence supports the finding.

The audit does not create the criteria. A weak standard can be audited competently and still produce a weak conclusion. Nor does an audit examine everything. Scope may exclude subcontractors, seasonal labour, purchasing practices, environmental effects outside a site or events that occur when the auditor is absent. A clean conclusion therefore means that the evidence sampled within scope supported the criteria used.

It does not mean that no problem exists elsewhere. The 2013 Rana Plaza disaster became a global reminder of this limitation. Factory assessment had become routine across apparel supply chains, yet catastrophic building, governance and worker-safety risks were not prevented. The lesson was not that audits have no value.

It was that a periodic site visit cannot compensate for fragmented responsibility, narrow criteria, weak worker voice, purchasing pressure or absent remediation. Sampling is unavoidable. Auditors cannot interview every worker, inspect every plot or recalculate every transaction. They select evidence according to risk, materiality and professional judgement. The conclusion is therefore supported, not omniscient.

Management may also prepare records for the visit, workers may fear retaliation, and conditions may vary by season or shift. Triangulation across documents, observation, interviews and external data helps, but uncertainty remains. Independence is similarly more than organisational distance.

A third-party auditor can face commercial dependence on the client, pressure to finish within an unrealistic number of days or incentives to preserve a long relationship.

Internal auditors can be highly objective where governance protects their authority. The relevant question is whether conflicts are identified and controlled, whether evidence can be challenged and whether an unfavourable conclusion is genuinely possible. Audit quality depends on competence. A financial auditor, agronomist, labour-rights specialist and geospatial analyst bring different capabilities.

Complex sustainability claims often cross several disciplines. A technically neat checklist cannot substitute for understanding local law, seasonal work, land-use change, gendered risk or chain-of-custody controls. Findings are not the end of the process. An audit that records the same issue each year without effective corrective action becomes a ritual of recurrence.

The value lies in precise findings, proportionate response, verification of effectiveness and learning across sites. Where harm has occurred, remediation may also be required; closing a finding administratively is not the same as repairing its effects.

The discipline is to describe the audit honestly. State the criteria, scope, period, sites, sampling, method, assurance limitations and conclusion. Do not let the single word audited carry meanings the engagement never tested. Audit can strengthen accountability, but only when users can see what was examined, what was not and what happened after the finding.

Practical application

Define the audit objective and criteria before selecting the method. Build the programme around risk rather than a fixed checklist, and assign competent auditors with sufficient time, language and subject expertise. Protect confidential worker and community interviews and use multiple evidence sources. Report scope and limitations with the conclusion.

Track findings to correction, root-cause analysis, corrective action and effectiveness review. Analyse repeated findings across suppliers or regions for system causes, including buyer practices and scheme design.

Why it matters

Audits often sit between a sustainability claim and the people expected to trust it. When they are well designed, they reveal evidence gaps, test controls and support improvement. When their limits are hidden, they can provide confidence greater than the work justifies.

Common misconception

Audit is often treated as proof that an organisation or site is compliant in every respect. An audit provides a conclusion against specified criteria using selected evidence within a defined scope and time. It reduces uncertainty; it does not eliminate it.

Connections

ISO 19011 guides the audit process. Non-conformity translates evidence and requirements into a precise finding. Corrective Action addresses causes after findings, while Certification and Verification use audit evidence within different assurance arrangements.

A question worth asking

If a reader saw only the phrase independently audited, which boundary, exclusion or uncertainty in the actual engagement would they fail to understand?

Selected references

ISO 19011:2026. Guidelines for Auditing Management Systems. International Labour Organization. 2013. The Rana Plaza Accident and Its Aftermath. Power, M. 1997. The Audit Society: Rituals of Verification. Boiral, O. 2012. ISO Certificates as Organisational Degrees? Beyond the Rational Myths of the Certification Process. Organization Studies 33(5-6): 633-654. ISEAL Alliance. 2018.

Assuring Compliance with Social and Environmental Standards, Version 2. 0.

Review

Public comments appear only after editor acceptance. Draft comments stay in the review queue.

0
How people contribute

Reviewers choose the definition or an overview paragraph, leave a comment or replacement, and attach evidence or a source link.

How comments are used

Editors compare reviewer cards side by side. AI may help find agreement, conflicts, unsupported claims and possible source issues.

What gets published

Only an editor-accepted synthesis changes the public page. Reviewer identities are shown only with consent and verification.

No verified experts yet

Submitted reviews stay private until accepted.

Loading verified endorsements… Endorsements are not votes and never determine publication.

Endorse this definition

Endorse the exact version shown here. This is not a vote, and publication remains an editorial decision.

vmaster-draft-2026-08-10

Sign-in supplies your email for verification and necessary follow-up; it is not displayed publicly. We do not ask you to enter it again.

Sign in with a passwordless email link before submitting.

Review board

Comment on a specific line. Each reviewer stays separate until an editor accepts a merged draft.

1Separate reviewer cards

Each person comments on the definition or overview in their own draft card, with role, evidence and suggested wording kept together.

2AI comparison

AI can compare comments against the current text, flag conflicting claims, surface missing evidence and identify where reviewers agree.

3Editor synthesis

An editor merges compatible suggestions into a draft change, checks sources, records disagreements and decides what can be published.

Text to reviewChoose the exact definition or overview paragraph.
Reviewer commentDraft only. Not public until editor accepted.
Definition
Reviewer identityYour signed-in account identifies the submission. We use its email only for verification and necessary follow-up, and never display it publicly.
Before you submit

This proposal follows the editorial and AI-assistance rules. The live definition will not change until an editor accepts it.

  • Add the proposed wording or note.
  • Explain why the change is needed.
  • Ready
  • Ready

Sign in with a passwordless email link before submitting.

You can still save a draft, but completing these items makes editorial review faster. Multiple reviewers can suggest changes on the same text. Editors compare, merge, accept or decline them before any public change.