audit (external)
**External audit** is a **third-party assessment of an organization's quality management system conducted by an accredited certification body or customer auditor** — providing independent verification that the organization complies with quality standards (ISO 9001, IATF 16949, AS9100) and is capable of consistently delivering conforming products to customers.
**What Is an External Audit?**
- **Definition**: An independent assessment conducted by auditors from an accredited registrar (certification body) or by customer quality teams to verify compliance with applicable quality management standards and contractual requirements.
- **Types**: Certification audits (registrar), surveillance audits (annual), recertification audits (every 3 years), and customer audits (second-party).
- **Stakes**: Certification audit failure can result in loss of certification — preventing the organization from selling to customers who require it.
**Why External Audits Matter**
- **Certification Maintenance**: ISO 9001, IATF 16949, and AS9100 certifications require successful external audits — loss of certification means loss of market access.
- **Customer Confidence**: External audit results provide customers with independent assurance that the supplier's quality system is effective.
- **Business Requirement**: Many semiconductor customers mandate specific certifications and conduct their own supplier audits before awarding contracts.
- **Benchmarking**: External auditors bring cross-industry perspective and best practices — their observations often highlight improvement opportunities.
**External Audit Types**
- **Stage 1 (Documentation Review)**: Registrar reviews QMS documentation — quality manual, procedures, process maps — to verify adequacy before on-site audit.
- **Stage 2 (On-Site Audit)**: Registrar audits the implemented QMS on-site — interviews personnel, reviews records, observes processes, verifies compliance.
- **Surveillance Audit**: Annual on-site audit (typically 1-2 days) verifying continued compliance and improvement between full recertification audits.
- **Recertification Audit**: Full-scope on-site audit every 3 years to renew certification — covers all QMS clauses.
- **Customer (Second-Party) Audit**: Customer's quality team audits the supplier — may focus on specific products, processes, or concerns.
**Audit Preparation Best Practices**
- **Internal Audit First**: Complete internal audit cycle and close all findings before external audit date.
- **Management Review**: Conduct management review with current QMS performance data — auditors will verify this.
- **Record Readiness**: Ensure all quality records (calibration, training, CAPA, inspection) are current and accessible.
- **Employee Preparation**: Brief employees on audit protocol — answer honestly, show what is asked, don't volunteer extra information.
- **Corrective Action Closure**: Verify all open CAPAs from previous audits are effectively closed with supporting evidence.
External audits are **the ultimate validation of semiconductor manufacturing quality systems** — providing the independent, accredited assurance that customers, regulators, and the market require to trust that chips are produced under controlled, documented, and continuously improving processes.