SMS Auditing: 1st Party, 2nd Party, 3rd Party

SMS Auditing Model

SMS Auditing ModelOne of the more critical elements of an SMS is “auditing.”  In the Plan-Do-Check-Act model, auditing falls within the “CHECK” function. 

I like to say it’s the element that keeps us honest and informed.  And with that in mind, I break down my audits into three (3) layers:

→ 1st Party

→ 2nd Party

→ 3rd Party

Each type of audit has its pros and cons, and the fact that the facility is auditing is critical; who is doing it plays a role, but not as critical.

Here is how these audits work:

1st Party is a “self-audit.”  These are easy, but when done in an immature SMS, they are ripe for abuse, making them a numbers game with little to no quality.  That being said, these 1st Party audits are NECESSARY in shaping the culture; eventually, we will rely on our 1st Party Audits in a very big way.  But early on, these audits MUST be validated by 2nd Party and 3rd Party audits, and hopefully, the results will fall within a tolerance we can live with. 

Remember that the “safety team” also performs many of these audits. Although they are technically 2nd Party Audits, I always managed the safety team audits as a “VERIFICATION EXERCISE” more so than an auditing exercise.  In other words, the unit/department personnel audits should be conducted within the same tolerance as the safety team.  If there is a large discrepancy between what the safety team and other auditors are finding/missing, we MUST understand what is causing this gap.  I never fully expect an operator, maintenance tech, or even a supervisor or superintendent to find the same level of concerns that a safety team member will, but there has to be some level of agreement on just how wide a gap is acceptable and when we are outside that “risk tolerance” that we analysis WHY the gap is too large and work to close it.

 

2nd Party audits are when someone outside the Unit/Department comes over to conduct the audit.  These auditors are company employees, just removed from the “ownership” of any deficiencies identified.  Sometimes, these 2nd Party Auditors may be from outside the facility, such as Corporate EHS personnel, but they are within the company.  These auditors are excellent when auditing site/company-specific safety and health expectations.  But there is one significant conflict in these 2nd Party Auditors… If I let you slide on X, you have to let me slide as well when you come to my department/unit/plant.  Auditors can be impacted by the fear of writing a lot of findings and fearing that will result in retaliation when it is their turn to be audited.

 

Third-party Audits may be necessary in the early days of implementing a formal SMS, but they have drawbacks. Outside personnel may not have the knowledge and experience to audit the SMS at the facility or lack experience in specific manufacturing/processing methods. After all, a person outside the SMS should NOT know more about the elements than internal personnel.  However, in an immature SMS, having an unbiased set of eyes and ears examining the inner workings of the SMS is a good thing. 

 

I strongly suggest my clients use ALL three types of audits in the early days and that the audit data be kept in three (3) silos to be able to identify weaknesses associated with the 1st and 2nd Party Audits.  We eventually want to rely on our 1st Party audits as the majority of our audits; however, it takes time – sometimes years and even a decade for the SMS to mature to the point that we have trust and credibility in our internal auditing.  We build this trust and credibility by using the 2nd and 3rd Party audits to VALIDATE what the 1st Party Audits are finding AND MISSING. 

Lastly, auditing is a never-ending process, like all the SMS elements! In my professional opinion, it is one of the Top three elements for setting the facility up for success. It is, without a doubt, an exercise where quality prevails over quantity.  Do NOT let the auditing metrics become more about the number of audits being done than the findings identified!  As I said above, the safety team should be used to validate these 1st and 2nd Party audits.  Essentially, the safety team is auditing the auditors.  As the 1st and 2nd Party auditors get better at auditing and personnel come to believe their audits are making a difference, we can begin to rely more and more on our internal auditing and use 3rd Party at a lesser frequency and strictly as a means to VERIFY and VALIDATE the 1st and 2nd party audit results.

 

Scroll to Top