Third party inspection companies operate in a world where their credibility is their product. A client hires a TPI company not just to look at something — they hire them because an independent finding carries legal, contractual, and financial weight that the client's own opinion cannot. That credibility depends entirely on records: who inspected it, what they were authorised to inspect, what they found, and how the certificate was issued and controlled.
This guide covers what third party inspection is, why it exists, what ISO/IEC 17020 requires, what records TPI companies must maintain, the operational problems that most TPI companies face as they scale, and what software can do to solve them.
What Is Third Party Inspection?
Third party inspection (TPI) is the independent verification of quality, conformity, or compliance by a body that has no commercial interest in the outcome. To understand why it matters, it helps to understand the three-party model.
First party inspection is when a supplier or manufacturer inspects their own work. It is internal, useful for internal quality control, but carries an inherent conflict of interest — the supplier has a financial incentive for the product to pass. Second party inspection is when the buyer or client inspects the supplier's work — more rigorous, but still represents one commercial party's view. Third party inspection is performed by an independent body with no stake in whether the result is a pass or a failure. That independence is what makes a third party inspection certificate acceptable to banks, regulators, insurance underwriters, and project owners.
The types of inspection TPI companies perform span the full product lifecycle:
- Pre-shipment inspection (PSI) — verifying that goods meet the purchase order specification before they leave the factory or port
- In-process inspection — attending at a manufacturing facility during production to verify quality at critical stages
- Final inspection — confirming finished goods meet the agreed standard before acceptance
- Load inspection — verifying the quantity and condition of cargo at the point of loading
- Surveillance inspection — ongoing monitoring at a facility over a period of time, common in large fabrication projects
- Condition surveys — establishing the condition of an asset (ship, pipeline, structure) at a specific point in time
The clients who hire TPI companies are diverse. Banks and trade finance institutions require independent inspection certificates before releasing payment under a letter of credit. Insurance underwriters require condition surveys before issuing marine cargo or equipment cover. Governments require TPI certificates for imports of food, pharmaceuticals, steel, and other regulated products. Large manufacturers use TPI companies to provide supply chain assurance when they cannot station their own inspectors at every supplier facility. Oil and gas project owners and EPCs (Engineering, Procurement, and Construction contractors) require TPI at fabrication yards to verify that equipment meets the engineering specification before it is shipped to site.
Why Third Party Inspection Is Required
TPI is not optional in many commercial and regulatory contexts. Understanding the drivers clarifies why records and documentation are so critical — because the inspection certificate often has legal and financial consequences.
Trade finance: A letter of credit (LC) is one of the most common instruments in international trade. The issuing bank will not release payment until the seller presents a set of stipulated documents — and the LC often specifically requires a clean inspection certificate from a named or approved TPI company. The certificate becomes a financial instrument in its own right. Any discrepancy between the certificate and the LC terms can delay payment or create a documentary credit dispute. This is why the accuracy, traceability, and authenticity of the inspection certificate matter enormously.
Import and export regulations: Many governments require TPI certification for specific product categories before customs clearance. Food and agricultural products, pharmaceuticals, oil and petrochemical products, steel and construction materials — these are common categories where a government-mandated pre-shipment inspection is required, often by an accredited body operating under that country's import control regime.
Project quality assurance in oil and gas: Major oil and gas projects (upstream, midstream, downstream) require third party inspection at fabrication yards and manufacturer premises as part of the project quality plan. The TPI company attends on behalf of the project owner or the EPC contractor to verify that pressure vessels, piping, structural steel, and other critical items are manufactured to the correct specification and applicable code (ASME, API, EN) before they are shipped to site. Inspection records become part of the permanent project documentation.
Marine cargo insurance: Before a marine insurance policy is issued on a cargo, the insurer may require a pre-loading survey establishing the condition of the goods. If a claim is later made, the inspection certificate is the baseline — it establishes what condition the cargo was in before the voyage, which determines liability.
Consumer product safety: Electrical goods, mechanical equipment, toys, and personal protective equipment are subject to safety directives in most markets. TPI companies are engaged to verify that products meet the relevant safety standards (IEC, EN, ASTM) and to issue conformity certificates that accompany the product to market.
Supply chain risk: For large buyers sourcing from multiple suppliers in multiple countries, it is impractical to station their own staff at every factory. A TPI company provides eyes on the ground — verifying that a supplier in a remote location is actually producing the goods to specification and not cutting corners that would only become apparent on arrival.
The sectors most dependent on TPI include: oil and gas, maritime and shipping, food and agriculture, steel and metals, construction, consumer products, pharmaceuticals, and automotive supply chains.
ISO/IEC 17020: The Standard for Inspection Bodies
ISO/IEC 17020 is the international standard that specifies requirements for the competence of inspection bodies. It is the framework that gives a TPI company's inspection certificates credibility in regulated and contractual contexts — the equivalent of ISO 17025 for testing laboratories. Accreditation to ISO 17020 by a recognised national accreditation body signals to clients, regulators, and courts that the inspection company's processes are independently verified to meet international requirements.
Types of inspection bodies under ISO 17020:
- Type A — fully independent inspection body with no ties to any party in the supply chain it inspects. This is the highest level of independence and the type most likely to be accepted by regulatory authorities and financial institutions.
- Type B — an inspection body that is part of a larger organisation (e.g., a manufacturer's inspection division) and performs inspections of products or services not produced by that organisation.
- Type C — an inspection body that can inspect both its own organisation's products and those of other parties, subject to specific safeguards for impartiality.
The key requirements ISO 17020 places on inspection bodies:
Structural requirements: The inspection body must be legally identifiable, must have documented policies to ensure impartiality, and must ensure that commercial, financial, or other pressures do not compromise its inspection findings. For Type A bodies, this means no financial or contractual relationship with the parties whose products are being inspected.
Resource requirements: Inspection personnel must be competent for the types of inspection they perform — their qualifications, training, and experience must be documented, and authorisation to perform specific inspection activities must be formally granted and recorded. Measuring and testing equipment used during inspection must be calibrated with traceability to national or international standards, and calibration records must be maintained.
Process requirements: Inspection activities must follow documented procedures. The inspection record must capture sufficient information to enable the inspection to be repeated under similar conditions — meaning that the checklist, the criteria applied, the instruments used, the findings, and any non-conformances must all be documented. The inspection report (or certificate) must be formally issued with identified inspector, scope, date, findings, and conclusions.
Records and reports: ISO 17020 requires that inspection records be retained for a period consistent with contractual, regulatory, and legal obligations — typically a minimum of five years, though this can be longer for safety-critical industries. Records must be legible, retrievable, and protected against unauthorised alteration.
ISO 17020 vs ISO 17025: ISO 17025 applies to testing and calibration laboratories — organisations that measure properties using calibrated equipment and report quantitative results with measurement uncertainty. ISO 17020 applies to inspection bodies — organisations that examine a product, process, or installation and form a professional judgement about conformity. The two standards have structural similarities but distinct technical requirements. An organisation that does both testing and inspection may need to be accredited to both.
Accreditation bodies that assess against ISO 17020 include NATA (Australia), UKAS (United Kingdom), NABL (India), A2LA (United States), DAkkS (Germany), and their equivalents in most countries. These bodies are themselves signatories to mutual recognition agreements (the ILAC MRA) which means that accreditation in one country is recognised in others — a critical factor for TPI companies operating across borders.
Records Every TPI Company Must Keep
This is the operational reality of running a TPI company: the records burden is substantial, and the consequences of a gap are severe. A client dispute, a regulatory audit, or an insurance claim can go back years. The following five categories cover the core records obligations.
1. Inspection Job Records
Every inspection job generates a set of records that must be retained as a complete, retrievable package:
- Job instruction or purchase order — the client's instruction to inspect, specifying the scope, location, criteria, and any specific requirements. This is the contract record for the job.
- Inspection plan — the plan developed by the TPI company specifying what will be inspected, against which criteria, at which checkpoints, using which methods. This documents that the inspection was planned and executed systematically.
- Inspector assignment record — which named inspector was assigned to the job, and evidence that they were authorised for this type of inspection on this date.
- Checklists and field data — the actual data captured during the inspection: dimensional measurements, visual findings, test results, AQL sampling data, or NDT readings. This is the objective evidence behind the certificate.
- Photographs and supporting evidence — photographs documenting findings (conforming and non-conforming), material certificates reviewed, weld maps checked, or other physical evidence.
- Non-conformance reports — if the inspection identifies items that do not meet the specified criteria, the non-conformances must be formally recorded with description, severity, and any client disposition.
- Inspection certificate or report — the final issued document: signed or authenticated, dated, clearly identifying the inspector and the accreditation body, the scope inspected, the criteria applied, the findings, and the conclusion (conforming / not conforming / conditionally conforming).
2. Personnel Records
When a client or accreditation body asks whether your inspector was qualified for the scope they performed, you need to be able to answer that question in minutes — not hours. Personnel records must include:
- Qualifications and certifications — copies of all relevant certifications (CSWIP, PCN, ASNT, AWS CWI, BGAS, API 510/570/653, marine surveyor qualifications, etc.) with issue dates, certification bodies, and expiry dates
- Training records — internal and external training completed, with dates and topics
- Competency assessments — records of witnessed assessments or mentored inspections, particularly for inspectors new to a discipline
- Authorisation matrix — a formal record of which inspection types each inspector is authorised to perform, signed off by management. This is a specific ISO 17020 requirement and a common point of scrutiny in accreditation assessments.
- Expiry management — a system for tracking certification expiry dates so that inspectors are not assigned to work for which their certification has lapsed. An inspector performing work outside their current certification scope is one of the most serious findings an accreditation body can make.
For a detailed guide to tracking inspector qualifications, see our post on NDT personnel certification tracking.
3. Equipment and Calibration Records
Measurements and observations made with an uncalibrated instrument are not defensible. TPI companies must maintain:
- Calibration certificates for every measuring instrument used in inspection work — ultrasonic thickness gauges, temperature probes, hardness testers, coating dry film thickness gauges, dimensional measurement tools
- Calibration due dates — the date by which each instrument must next be calibrated, tracked so that overdue instruments are not taken into the field
- Traceability — each calibration certificate must reference the standard to which it was calibrated, and that standard must be traceable (directly or through a chain) to a national measurement standard
- Equipment issue records — when an instrument is issued to an inspector for a specific job, there should be a record of which instrument (identified by asset number or serial number) was used on which job. This allows the calibration status at the time of inspection to be verified retrospectively if needed.
4. Client and Contract Records
For clients who use a TPI company repeatedly — across multiple projects, shipments, or assets — there is a history that must be maintained:
- Client contract and scope of work — the master agreement or framework contract, plus job-specific scope documents
- Client asset register — for clients whose equipment is inspected on a recurring basis (pressure vessels, lifting equipment, above-ground storage tanks), a register of which assets have been inspected, when, by whom, and what was found
- Inspection history — the ability to retrieve all inspection records for a given client, asset, or shipment over time. This is valuable for the client (asset lifecycle management) and essential for the TPI company if a dispute or claim arises years after the inspection.
5. QMS Records
ISO 17020 accreditation requires a functioning quality management system, and the records of that system must be maintained:
- Internal audit records — the audit plan, the audit report, findings raised, and evidence of closure for all findings
- Non-conformance and CAPA register — all non-conformances raised within the QMS (not just those found during inspections), corrective actions taken, root cause analysis, and verification of effectiveness
- Management review records — minutes of management review meetings, including review of QMS performance, resource adequacy, and decisions made
- Document control register — current revision status of all controlled documents (inspection procedures, checklists, report templates, work instructions), with approval records and issue dates
Inspection Sectors and Their Specific Needs
The core records obligations above apply to all TPI companies, but each sector adds its own layer of technical and regulatory specifics.
Oil and Gas: Weld inspection records are central — weld maps, welder qualifications, weld procedure specifications (WPS) and procedure qualification records (PQR), NDT results (RT, UT, MT, PT), and pressure test records must all be traceable back to the individual weld and the inspector who accepted it. Material traceability records (Mill Test Certificates / MTCs) are reviewed against the purchase specification. API codes (API 650, 510, 570, 1104) define the acceptance criteria. Inspectors in this sector typically hold CSWIP 3.1/3.2, PCN Level 2/3, or AWS CWI qualifications. The inspection record pack for a fabricated pressure vessel can run to hundreds of pages and must be handed over as part of the final project documentation package.
Marine and Ship Inspection: Marine inspection covers hull condition surveys, cargo inspection at loading and discharge, bunker quantity surveys (BQS), draft surveys, and fitness-for-voyage certificates. Classification society requirements from Lloyd's Register, Bureau Veritas, DNV, and ABS define the technical standard. Cargo inspection certificates (covering quantity, condition, and stowage) become part of the bill of lading documentation. Marine surveyors must hold relevant qualifications from professional bodies such as the Institute of Marine Engineers, Scientists and Technologists (IMarEST) or equivalent national bodies.
Food and Agriculture: Pre-export inspection for grains, oilseeds, soft commodities, and fresh produce involves sampling, grading, moisture content measurement, and fumigation certification. Certificates must reference the sampling method (ISO, GAFTA, or FOSFA sampling procedures), the quantity surveyed, and the analytical results. HACCP records for hygienically sensitive products, phytosanitary certificates, and fumigation treatment records are part of the inspection file. Major players in this space — SGS, Bureau Veritas, Intertek — operate under GAFTA/FOSFA Rules and government-mandated inspection programs.
Steel and Metals: Dimensional inspection records (measuring that fabricated items are within the tolerance specified), positive material identification (PMI) records verifying that the alloy composition matches the material certificate, MTC review records, and weld map review form the core of steel inspection documentation. For structural steel going into a building or industrial facility, the inspection record is part of the permanent structural file that may need to be retrievable for the life of the structure.
Construction: Structural steel inspections, concrete pour records, coating inspection (holiday testing, dry film thickness, adhesion), lifting equipment inspection (cranes, slings, shackles), and non-destructive examination of welds in structural applications. In many jurisdictions, statutory inspection of lifting equipment is a legal requirement at defined intervals, and the inspection certificate must be held by the equipment owner. See our guide on statutory inspection and asset management for more on this.
Consumer Products: Pre-shipment inspection (PSI) against AQL (Acceptable Quality Level) sampling plans, safety testing verification, and conformity of product to purchase order specification. Inspection records must capture the AQL level applied, the sample size drawn, the number of defects found by category (critical, major, minor), and the pass/fail determination. For products carrying a CE mark or other regulatory conformity marking, the inspection record forms part of the technical file that must be retained by the manufacturer.
The 5 Biggest Operational Problems for TPI Companies
Most TPI companies that are growing beyond a handful of inspectors hit the same five problems in roughly the same order. They are operational problems, but they create compliance risk.
1. Inspector in the field, records on paper
An inspector at a remote fabrication yard, on a vessel at anchor, or at a factory in another country fills in a paper checklist. The checklist travels back to the office — by hand, by courier, or photographed and emailed. The data then needs to be transcribed into the report. In the meantime, the client is calling for the certificate. Data gets lost, photographs are not properly referenced to the findings they document, and the report that is eventually issued may not accurately reflect what was captured in the field. Paper-based field data capture is the single biggest source of data quality problems in TPI operations.
2. Certificate issuance is a manual process
The typical certificate workflow in a small TPI company: inspector submits report, office staff populate a Word template, a manager reviews and signs (or adds a scanned signature), a PDF is emailed to the client. There is no unique certificate number that can be independently verified. There is no audit trail showing who approved it and when. If the client loses the certificate and asks for a copy, someone has to find the email thread it was originally sent on. If there is a dispute about whether a certificate is genuine or has been altered, there is no way to verify it. For a TPI company whose certificates have financial or legal consequences, this is a serious vulnerability.
3. No real-time visibility on inspector qualifications
A client rings up: "We need to know that the inspector you sent to our supplier last March was qualified to CSWIP 3.1 at the time of the inspection." The operations manager opens a spreadsheet, searches for the inspector's name, tries to find when that particular CSWIP certificate was issued and when it expired, and cross-references it with the job date. If the company has grown to fifteen or twenty inspectors, each with multiple certifications across different disciplines, this search can take hours. For an accreditation assessor, it should take two minutes. The authorisation matrix and certification records need to be instantly accessible by job, by inspector, and by date.
4. No client portal — clients request records by phone and email
For clients who use a TPI company regularly — a trading house inspecting multiple shipments per month, or a manufacturer with ongoing supplier surveillance — the ability to access their own inspection history online is not a luxury, it is an operational expectation. When it does not exist, the client rings the office whenever they need a previous certificate, or when they want to know the status of a job in progress. This creates an administrative burden on the TPI company's office staff that scales with the number of active clients. A client portal where clients can log in, see their job history, and download certificates removes this burden entirely.
5. Job management runs on spreadsheets
Booking a job, assigning an inspector, tracking the status of a job in progress, flagging jobs that are overdue for a report, and managing the schedule when multiple inspectors are working simultaneously — these functions in most small TPI companies live in a spreadsheet that one person owns and everyone else asks. When that person is on leave, or when two people edit the spreadsheet simultaneously, or when a booking is made and not entered, jobs get dropped. There is no real-time view of what is open, what is in progress, what is overdue, and what is awaiting client approval.
What Software Should a TPI Company Use?
The software question for a TPI company is not whether to use software — it is whether to use software that was designed for this type of business, or to assemble a patchwork of generic tools and accept the limitations that come with it.
A TPI company's software needs to cover the following functional areas in an integrated way:
- Job management — booking, scheduling, status tracking, client and scope assignment
- Inspector dispatch — assigning the right inspector (checking qualifications and availability), recording the assignment, and managing travel and access logistics
- Field data capture — digital checklists and forms that inspectors complete on a tablet or phone in the field, with photograph attachment, GPS stamping, and offline capability
- Report generation — automated population of report templates from field data, with customisable formats for different clients or inspection types
- Certificate issuance with QR verification — issuing numbered certificates with a QR code that any party can scan to verify authenticity and retrieve the original. This solves the certificate integrity problem at the point of issuance.
- Client portal — a secure portal where each client can log in to see the status of current jobs and access their complete inspection history and certificates
- Calibration tracking — equipment register, calibration due dates, certificate storage, and alerts when instruments are approaching calibration due dates
- Personnel qualifications — the full qualification and certification record for each inspector, the authorisation matrix, expiry date alerts, and the ability to verify at any historical date which inspectors were authorised for a given scope
- ISO 17020 QMS — document control, internal audit management, non-conformance and CAPA register, and management review — built into the same platform as the operational records so that audit evidence does not need to be assembled from separate systems
Generic tools — why they fall short: Excel, Word, Dropbox, and email are cheap and familiar. At low volume, they work well enough. But they do not scale. There is no authorisation control on who can edit a calibration spreadsheet. There is no alert when a certification is about to expire. There is no way to generate a unique, verifiable certificate. And when an accreditation assessor asks to see all inspections where a particular instrument was used in the past three years, a spreadsheet cannot answer that question. The five problems described in the previous section are the direct consequence of running a TPI operation on generic tools.
Generic project management tools — Asana, Monday, Trello, Notion — are better than spreadsheets for job tracking, but they have no concept of inspector qualifications, calibration traceability, QR-verified certificate issuance, or ISO 17020 document control. They solve one of the five problems (job visibility) while leaving the other four untouched.
Purpose-built TIC software is designed around the workflows of testing, inspection, and certification businesses. It understands that a job has an inspector with qualifications, that the inspector uses instruments that need to be calibrated, that the output is a certificate that a client needs to access, and that the whole operation needs to be auditable against a quality standard. The investment is higher than a spreadsheet, but the compliance risk it eliminates and the administrative time it recovers make it the only viable option for a TPI company operating at scale or under accreditation.
OMS is built specifically for TIC companies — testing laboratories, inspection bodies, and certification companies. It covers all of the functional areas above in a single platform: job management, inspector dispatch with qualification checking, digital field data capture, automated report generation, QR-verified certificate issuance, a client portal, calibration tracking with due date alerts, personnel qualification management with the full authorisation matrix, and a complete ISO 17020-aligned QMS with document control, internal audit, CAPA, and management review.
OMS is used by NDT inspection companies, welding inspection bodies, NDT and inspection service providers, and multi-discipline TPI companies operating across oil and gas, construction, and industrial sectors. For a detailed look at how OMS handles inspection workflows, see our guide to streamlining inspection and certification workflows.
The question TPI companies most often ask when evaluating software is: "Will this reduce the time we spend on administration, and will it make us more audit-ready?" The answer, for a platform that is purpose-built for this sector, is yes to both. The operational efficiency gains come from eliminating manual transcription, automating report generation, and giving clients self-service access to their own records. The compliance gains come from having all records — job records, personnel records, equipment records, and QMS records — in one searchable, auditable system that does not depend on any single individual to maintain.
Frequently Asked Questions
- What is the difference between first, second and third party inspection?
- First party inspection is when a supplier or manufacturer inspects their own work — it is internal and carries an inherent conflict of interest. Second party inspection is when the customer or buyer inspects the supplier's work — it is more rigorous but still represents one party's commercial interest. Third party inspection is carried out by an independent body that has no financial stake in the outcome of the transaction or project. Because the third party has nothing to gain from a pass or fail result, its findings carry legal, contractual, and regulatory weight that first and second party inspections cannot provide.
- What qualifications do third party inspectors need?
- Inspector qualifications depend on the sector and the type of inspection being performed. For weld inspection: CSWIP (Certification Scheme for Welding and Inspection Personnel) or PCN (Personnel Certification in NDT) in the UK/Australia, or AWS CWI (Certified Welding Inspector) in North America. For NDT: PCN, ASNT, or CSWIP NDT certifications at Level 2 or Level 3. For coating inspection: BGAS-CSWIP or NACE/AMPP certifications. For oil and gas pressure equipment: API qualifications (API 510, 570, 653). Marine surveyors typically hold qualifications from Lloyd's Register, Bureau Veritas, or DNV, or hold membership of professional bodies such as the Institute of Marine Engineers.
- What records must a third party inspection company keep?
- A third party inspection company must maintain records across five main categories: (1) Inspection job records — job instructions, inspection plans, checklists, field data, photographs, non-conformance reports, and the signed inspection certificate or report. (2) Personnel records — inspector qualifications, certifications (with expiry dates), training records, competency assessments, and an authorisation matrix showing who is approved for which inspection types. (3) Equipment records — calibration certificates for all measuring instruments, calibration due dates, and traceability to national or international standards. (4) Client and contract records — contracts, scope of work, and inspection history per client asset or shipment. (5) QMS records — internal audit records, CAPA register, management review minutes, and controlled document register.
- What is ISO 17020 and who needs it?
- ISO/IEC 17020 is the international standard that specifies requirements for inspection bodies — organisations that perform inspection as a service for clients. It covers structural requirements (impartiality, legal structure), resource requirements (inspector competency, equipment calibration), and process requirements (inspection procedures, records, reporting). Any inspection body that wants to offer credible, independently verified inspection services typically seeks accreditation to ISO 17020 from a national accreditation body such as NATA (Australia), UKAS (UK), NABL (India), A2LA (USA), or DAkkS (Germany). Accreditation is often required by government regulations, client contracts, and industry standards — particularly in oil and gas, food safety, trade finance, and marine cargo sectors.
- What software do third party inspection companies use?
- Many TPI companies start with general tools — spreadsheets for job scheduling, Word templates for reports, Dropbox for storing certificates. These work at low volume but create serious compliance and operational problems as the company grows: records are hard to retrieve for audits, certificates have no authenticity verification, inspector qualifications are tracked manually, and there is no real-time job visibility. Purpose-built TIC (Testing, Inspection, and Certification) software solves these problems by providing job management, inspector dispatch, digital field data capture, automated report generation, QR-verified certificate issuance, a client portal, calibration tracking, and an ISO 17020 compliant QMS in a single platform.