A finding only means something relative to stated criteria. Before evidence is collected, an audit has to fix what it is measuring against — a regulation, a standard, a contract, or a documented internal requirement — and what falls inside the boundary. Assessments that skip that step produce observations that cannot be disputed or acted on, because nobody agreed in advance what "good" looked like.
ISO 19011:2018 sets seven principles for auditing management systems, and two of them do most of the work. The evidence-based approach means a conclusion must trace back to something verifiable — a record, a configuration, an observation, a test result — rather than to an assurance given in a meeting. Fair presentation means the report states what was found including obstacles, disagreements, and anything the audit could not reach.
The standard also distinguishes three audit types, and the distinction is commercial as much as technical. First-party audits are internal, run by or for the organisation itself. Second-party audits are conducted on suppliers or by customers. Third-party audits are performed by an independent body for certification. Up Secure works in the first two categories: internal audit on your behalf, and audits of your suppliers. Certification remains with an accredited body.
That separation is not a preference. Under clause 5.2.7 of ISO/IEC 17021-1, a certification body may not certify a management system it has provided consultancy on for at least two years after that consultancy ends. Choosing who prepares you and who certifies you is therefore a sequencing decision worth making early, because getting it wrong can delay a certificate by two years.