M S Ray
0 comment
02 Oct, 2026
An organization may have an inspiring vision, a clearly stated mission, well-developed policies, ambitious objectives and beautifully documented procedures, but there is one fundamental question that eventually has to be answered: is all this management intent actually happening at ground zero? To me, this is where the real value of internal audit begins. I have always regarded internal audit as one of the most important elements of a management system, not merely because ISO requires it and certainly not because a certification auditor expects to see an internal audit report, but because it acts as the health-check process of the organization.
A doctor does not examine a patient merely to confirm that all the expected organs exist. The purpose is to understand whether those organs are functioning properly, whether warning signs are developing, and whether intervention is necessary before a manageable weakness becomes a serious condition. Internal auditing should perform a similar role for a management system. It should help management understand what is being done well, what is not happening as intended, where changes have created new risks, where controls are weakening, and what needs to improve before a problem becomes a failure.
This philosophy applies whether we are talking about quality, occupational health and safety, environmental management, food safety, energy management, information security, artificial intelligence, business continuity or any other management system. The basic principle remains remarkably similar: understand what the organization intends to achieve, understand the processes through which those results are expected, examine objective evidence, evaluate the controls, and determine whether the system is functioning effectively and remains capable of achieving its intended results.
Internal auditing is sometimes reduced to a much narrower exercise. A procedure exists, so the auditor asks whether the employee is following it. That question is necessary, but it is not sufficient. A competent auditor should also be capable of asking whether the procedure itself remains suitable. A procedure may be followed perfectly and yet no longer be effective. Technology may have changed, customer expectations may have changed, risks may have changed, the organization may have grown, regulatory obligations may have evolved, or the process itself may have become unnecessarily complicated. Employees may even be performing additional unofficial steps because the written procedure no longer reflects operational reality.
If an auditor merely records “conforming” because everybody followed the documented procedure, an enormous opportunity may have been missed. Internal audit should therefore verify conformity with established criteria, but it should also help management understand whether its arrangements remain suitable, adequate and effective. This does not mean that an auditor should raise a nonconformity simply because he or she personally prefers another method. A nonconformity must relate to an identifiable requirement. However, audit evidence can reveal risk, weakness, inefficiency and opportunities for improvement, which is why auditing should never become a mechanical checklist exercise. It requires professional judgement.
Top management establishes the broad direction of an organization through its vision, mission, policies, objectives, values, strategic direction and commitments to customers, employees, regulators, investors, society and other interested parties. But all those statements eventually have to travel through the organization. They become departmental objectives, processes, responsibilities, work instructions, operational controls, purchasing requirements, inspection criteria, training arrangements, maintenance schedules, safety controls and performance measures. Ultimately, they reach the person who actually performs the work.
That is what I call ground zero. It may be the machine operator, the welder, the nurse, the engineer, the inspector, the customer-service representative, the driver, the purchasing executive, the person approving a design or the technician maintaining critical equipment. A good internal auditor can start at ground zero and follow the process backwards. The auditor observes what is actually happening, speaks to the people doing the work, examines outputs and records, understands interfaces, and progressively connects those activities back to process objectives, departmental objectives, management policies and ultimately the strategic intent of top management.
The real question becomes: is what I am seeing here the operational expression of what leadership said it wanted to achieve? When that connection exists throughout the organization, vision and policy stop being framed statements hanging on the wall. They become behaviour. Behaviour creates consistent processes, processes create products and services, products and services create customer experience, and repeated customer experience eventually creates the organizational brand. This is why internal audit can be far more strategic than many organizations realize.
A mature internal audit programme should also recognize that not every process deserves identical audit attention. A routine administrative process that has operated reliably for years does not necessarily require the same audit intensity as a high-risk production operation, a safety-critical activity, a process undergoing significant change or one associated with repeated customer dissatisfaction. Audit frequency and depth should therefore reflect risk, importance, performance, previous weaknesses, changes and other indicators that tell management where greater assurance is required.
The first priority should be the processes that directly determine whether the organization produces its intended results. These may need to be audited more frequently, more deeply or with larger samples because they directly influence the customer, product, service, safety, environment or business outcome. The question is not whether every department received one audit during the year. The more important question is whether the processes upon which the organization depends are sufficiently robust to deliver the intended result consistently.
A second priority is previous weaknesses. Suppose an earlier audit identified a nonconformity, a corrective action was initiated, a root cause was identified, a procedure was changed, personnel were trained and the corrective-action record was subsequently marked “closed.” Is the problem really closed? Not necessarily. A completed corrective-action form does not prove that the problem has disappeared. A later audit should determine whether the action was actually implemented and, more importantly, whether it was effective. Did the problem recur? Did a similar problem appear elsewhere? Did performance improve? Was the real cause removed, or merely the visible symptom? Internal auditing can protect management from one of the most dangerous illusions in a management system: believing that a problem has been solved because the paperwork has been completed.
Changes are another important trigger for audit attention. A new technology, a redesigned process flow, a new ERP system, automation, artificial intelligence, organizational restructuring, a new machine, a different supplier, a new product, a revised formulation or a new method of working may all represent genuine opportunities for improvement. Yet every change can also alter existing controls. An internal audit conducted after significant change can ask whether the expected benefit has actually been achieved, what unintended risks may have been introduced, whether people were adequately prepared, whether the new controls are working and whether another part of the process has been adversely affected.
Customer feedback and performance trends can add another powerful perspective. A management system may appear satisfactory when viewed only through procedures and records, yet customer complaints, warranty trends, repeat service issues, delayed deliveries, rework, product returns or deteriorating satisfaction indicators may be telling a different story. These signals should help management decide where audit attention may provide greater value. In this way, the audit programme becomes responsive to the actual health of the business rather than being driven simply by dates on a calendar.
Internal auditing should also recognize that organizations are not collections of isolated departments. Within the same organization, functions constantly serve one another. Design provides information to production, purchasing provides materials to operations, human resources provides competent personnel, maintenance provides equipment availability, information technology provides systems, laboratories provide test results, stores provide materials, production provides finished products to inspection and inspection provides assurance to dispatch.
Each function is therefore simultaneously somebody’s supplier and somebody else’s customer. A failure at one interface becomes another department’s problem and, if the chain deteriorates sufficiently, it eventually becomes the external customer’s problem. A process-based internal audit therefore needs to follow these interactions. Instead of merely asking whether Purchasing complies with its procedure, the auditor should ask whether Purchasing is providing Operations with the right materials, at the right time, from capable suppliers and with the necessary controls to achieve the final customer requirement. That is a much richer audit question.
The same philosophy eventually takes us beyond the organization itself. Here, the terminology must remain technically correct. When an organization audits itself, it is conducting a first-party or internal audit. When it audits a supplier, contractor or external provider, it is conducting a second-party audit. Certification audits are third-party audits. The categories are different, but the management philosophy is connected.
Internal audits help us understand the health of our own management system. Second-party audits extend the same disciplined thinking towards the organizations that help us serve our customers. We should first ask ourselves whether we are capable of serving our customer consistently, and then, where our performance depends significantly upon others, we must also ask whether those who serve us are capable of helping us serve that customer consistently.
This is not about confusing internal audit with supplier audit. They remain different categories of audit. It is about recognizing that organizational assurance cannot stop artificially at the factory gate when critical processes continue beyond it.
No organization exists alone. This becomes particularly obvious in industries such as oil and gas. A major oil company may own the assets, possess enormous technological knowledge and establish the policies, procedures, engineering specifications and operating controls necessary to ensure that its facilities operate safely and reliably. Yet enormous portions of its activity may depend upon external providers. Geological surveys, drilling operations, drilling-fluid services, construction, inspection, NDT, maintenance, transportation, chemicals, pipes, valves, pumps, instruments, specialist testing, shutdown maintenance and asset-integrity activities may all depend upon contractors and suppliers.
The organization therefore becomes part of an enormous interconnected ecosystem. One inadequately controlled activity can have consequences far beyond the contractor performing it. A defective valve, an unsuitable chemical, an improperly manufactured pipe, an unqualified welder, an uncontrolled hot-work activity, a maintenance task without adequate isolation or a risk assessment that fails to identify a significant hazard can jeopardize production, people, equipment, the environment, reputation and business continuity. Assessing the capability of critical external providers is therefore not merely a procurement activity; it is part of organizational risk management.
This leads to what I consider a very important management philosophy: we examine ourselves honestly, and we work with those who serve us so that together we can serve the final customer better.
Second-party auditing should therefore not become an exercise in policing suppliers. The purpose should not simply be to find faults that can later be used to impose penalties. Suppliers must, of course, meet agreed requirements, and poor performance cannot simply be accepted. But mature organizations recognize that a capable supplier is an organizational asset. When an important external provider becomes stronger, our own supply chain becomes stronger. When its quality improves, our risk reduces. When its people become more competent, our confidence increases. When its processes become resilient, our continuity improves. And when the relationship is founded on mutual respect, that supplier may support the organization during difficult situations in ways that no contract could ever completely anticipate.
This is where the Quality Management Principle of relationship management becomes very real. If an organization sees an external provider merely as someone from whom the lowest possible price must be extracted, the relationship can gradually become adversarial. The buyer tries to squeeze every possible amount from the seller, the seller tries to recover margin somewhere else, trust deteriorates, investment reduces and capability may weaken. Eventually, the buyer may discover that weakening a strategically important supplier has weakened its own supply chain.
There is nothing wrong with protecting organizational profitability. Businesses must remain financially sustainable and they have responsibilities towards owners, investors, employees and other interested parties. Commercial discipline is essential. But sustainability cannot logically mean that one organization must remain healthy even if every organization upon which it depends becomes unhealthy. That is a narrow and ultimately short-sighted interpretation of strategy.
The more mature question is how to build a supply ecosystem in which every party remains accountable for performance while the relationship remains commercially viable and mutually beneficial. A capable external provider should therefore increasingly be viewed as a partner in value creation, particularly where that provider is integral to the product or service delivered to the final customer.
I have seen this philosophy tested during difficult circumstances. In audits involving organizations operating under challenging geopolitical conditions, I have seen suppliers go significantly beyond normal expectations to support their principal customers. Why did they do so? Not simply because a purchase order required them to. Many of these relationships had been built over years through mutual respect, fair dealing and an understanding that both organizations depended upon one another. When circumstances became difficult, the strength of that relationship became visible.
There is an important lesson here. An organization cannot spend years treating a critical external provider solely as a party whose commercial position should be weakened at every opportunity and then suddenly expect extraordinary loyalty when a crisis arrives. Relationships, like management systems, reveal their true strength under stress. A healthy supply chain can therefore become an important part of organizational resilience.
There is another dimension that good auditing should reveal. If an external provider repeatedly fails, the organization should certainly examine the supplier, but it should also examine itself. Were requirements clearly specified? Were changes properly communicated? Were technical expectations understood? Was the supplier selected primarily on the basis of lowest price despite known capability concerns? Were unrealistic delivery expectations imposed? Was sufficient information provided? Did procurement practices unintentionally create the very risk that the organization is now criticizing? Were performance problems addressed early, or only after they became critical?
Relationship management means being willing to examine both sides of the interface. That is the difference between fault finding and system thinking.
This is one of the reasons I personally find internal auditing enormously rewarding. A third-party certification audit has defined objectives, a specified scope, planned audit time and necessarily relies upon sampling. It performs a very important independent conformity-assessment role. But an organization’s internal audit programme belongs to the organization itself, and management is free to use it much more deeply.
If a critical process deserves another audit next month, audit it again. If a major change creates significant uncertainty, conduct a focused audit. If a customer complaint exposes a process weakness, follow that complaint through the entire process chain. If an earlier corrective action appears questionable, verify it again. If the available evidence requires a larger sample, take an adequate sample. If a strategic supplier needs attention, initiate an appropriate second-party audit. If management wants assurance that a major corporate initiative has genuinely reached operational level, audit it from the boardroom to ground zero.
The internal audit programme should not be designed around the minimum amount of auditing necessary to satisfy somebody else. It should be designed around the amount of assurance management itself needs. That difference in mindset changes everything.
Unfortunately, some organizations fall into a very different pattern. A few weeks before the certification audit, an internal audit is arranged. A checklist is completed, every department is marked satisfactory, a beautifully formatted report is produced and filed, and everybody feels ready for the external auditor. That may produce a document called an internal audit report, but has it produced meaningful assurance?
I would much rather see an internal audit report containing several genuine findings, thoughtful observations and meaningful opportunities for improvement than an immaculate document designed merely to demonstrate that everything is perfect. The purpose is not to make the organization look healthy. The purpose is to understand whether the organization is healthy.
The requirement for internal audit has existed from the earliest days of ISO 9001. In ISO 9001:1987, internal quality audit appeared under Clause 4.17. The 1994 edition retained the same clause numbering. With ISO 9001:2000 and ISO 9001:2008, internal audit became Clause 8.2.2, and with ISO 9001:2015 it moved to Clause 9.2. The wording and structure have evolved over time, but the essential management need has not changed. Management requires an objective mechanism for determining whether the system it designed is actually functioning as intended.
Earlier editions also placed strong emphasis on independence. The 2000 and 2008 versions, for example, explicitly stated that auditors should not audit their own work. More recent approaches emphasize auditor selection and the conduct of audits in a manner that ensures objectivity and impartiality. I appreciate this evolution because real organizations, particularly smaller ones, do not always operate within neat organizational compartments. Responsibilities overlap, people contribute to several processes and someone may occasionally need to audit an area with which he or she has previously had some involvement.
The true ethical test is whether the auditor can examine the evidence objectively and resist the temptation to protect his or her own interests. I have personally identified nonconformities in areas for which I had responsibility. As the process owner, I accepted them. Corrective actions were initiated and implemented, and where I considered additional independence desirable, I asked another competent person to verify the effectiveness of those actions. My objective was never to produce a report suggesting that I had done everything correctly. My objective was to understand the true state of conformity and effectiveness.
That, to me, represents the ethical foundation of auditing.
This is also why a valuable Lead Auditor course should do much more than explain what Clause 9.2 says. Knowing the requirement is necessary, but genuine competence develops when the learner understands how to audit the internal audit process itself. This requires a different level of thinking because an external auditor is effectively auditing the organization’s own mechanism for examining itself.
The first mistake would be to pick up one internal audit report, find that it has been completed properly, and conclude that the organization conforms to the intent of Clause 9.2. One successfully completed audit is not evidence that an effective internal audit programme exists. What needs to be understood is whether the organization has established an audit programme and whether that programme is being implemented, monitored and adjusted over time.
I often describe this as developing a bird’s-eye view of the organization. Management should step back from individual audits and look across the management system as a whole. Which processes are most critical? Which have experienced problems? Which have changed? Which processes have significant risks? Where have previous audits identified weaknesses? What are customer complaints and feedback trends telling us? Are there deteriorating operational indicators that deserve investigation? From this wider perspective, management can determine what needs to be audited, with what frequency, by what method and over what period of time.
The audit programme is therefore much more than a list of departments with twelve dates beside them. It should demonstrate management thinking. Critical processes may be audited more frequently. A previously stable process may require additional audit attention after a significant change. A process associated with repeated customer complaints may be brought forward in the programme. An area with repeated nonconformities may receive greater sampling or follow-up. Conversely, a mature, stable and low-risk process may not require the same intensity of attention as another area where assurance is more urgently needed.
Customer feedback and trends can be particularly valuable in this regard. Although they should not be confused with the specific factors explicitly stated within the internal-audit requirement, they can provide powerful risk-based information to management when determining audit priorities. If complaints are increasing, delivery performance is deteriorating, repeat repairs are rising, warranty failures are appearing or customer satisfaction is declining, an intelligent audit programme should ask whether these signals warrant deeper examination of the underlying processes. An audit programme should respond to the health of the organization rather than remain frozen simply because it was approved at the beginning of the year.
When auditing the internal audit process, I would therefore first examine the overall programme and ask whether it reflects the importance of the processes concerned, relevant changes and previous audit results. I would then look for evidence that the individual audits planned within that programme are actually being carried out. The programme provides the bird’s-eye view; the individual audit plans, evidence, findings and results demonstrate its implementation. Together they give confidence that internal auditing is a continuing management process rather than an isolated annual event.
The next important consideration is auditor competence. A technically knowledgeable person does not automatically become a competent auditor. Auditors need to understand the management system and the processes they are examining, but they must also know how to communicate, listen, probe and evaluate evidence objectively. They need to ask questions respectfully without intimidating the auditee, follow an audit trail when an answer leads somewhere unexpected, distinguish fact from assumption, recognize when evidence is insufficient and communicate findings in a manner that is factual, fair and constructive.
This human dimension of auditing is extremely important. An auditor who knows every clause number but cannot establish rapport may obtain very little meaningful evidence. At the other extreme, an auditor who is friendly but unwilling to probe beneath a convenient answer may fail to discover an important weakness. Professional auditing requires both competence and character: curiosity without hostility, independence without arrogance, firmness without disrespect and objectivity without losing the ability to understand the human realities of the workplace.
The audit programme should also define or provide for the frequency and methods of auditing, responsibilities, planning and reporting arrangements. Individual audits then need clear objectives, scope and criteria. These three concepts are fundamental. The objective explains what the audit is intended to achieve. The scope establishes the boundaries—what locations, functions, activities, processes or periods are included. The criteria define what the evidence will be compared against.
Those audit criteria may come from many sources. They can include the requirements of the relevant management-system standard, the organization’s own procedures and process requirements, customer-specific requirements, contractual obligations, legal or regulatory requirements, specifications, policies, codes or other commitments that the organization has accepted. An auditor therefore does not audit according to personal preference; objective evidence is evaluated against identifiable criteria.
The audit itself should then produce a factual representation of the state of affairs. Records of the audit results are essential because management needs reliable information from which decisions can be made. An audit report should not dramatize findings and it should not conceal them. It should present what was examined, what evidence was obtained and what conclusions can reasonably be drawn from that evidence. The principle of fair presentation is one of the foundations of professional auditing.
Where nonconformities are identified, the internal audit process should not end with the issuing of the finding. Appropriate correction and corrective action should follow. Here again, responsibilities need to be understood properly. The auditor identifies and reports the nonconformity based upon objective evidence and the applicable requirement. It would normally be the responsible process owner or management—not the auditor acting as consultant—who investigates the cause and determines the appropriate correction and corrective action.
The auditor nevertheless has an important role in evaluating what happens next. Does the proposed root-cause analysis make sense when compared with the evidence? Does the correction address the immediate problem? Does the corrective action address the cause sufficiently to reduce the likelihood of recurrence? Has the action actually been implemented? Is there evidence that it is effective? Merely accepting a statement such as “staff retrained” should not automatically close a significant nonconformity if the underlying cause was actually poor process design, unclear responsibility, inadequate resources or ineffective control.
The seriousness and nature of the nonconformity should also influence follow-up. For a relatively simple issue, documentary evidence may sometimes be sufficient to verify completion. For a significant or systemic failure, particularly where product quality, safety, environmental performance or major customer requirements are involved, a more rigorous follow-up may be justified. This could include additional sampling, interviews, examination of subsequent performance data or even a focused follow-up audit. The purpose is not to keep a nonconformity artificially open. The purpose is to obtain sufficient confidence that the weakness has actually been addressed and that the corrective action is effective.
This is why the internal audit process itself deserves to be audited with the same seriousness as production, design, procurement or any other critical process. If the mechanism by which an organization checks itself is weak, management may receive false assurance. A beautifully formatted audit programme, impressive checklists and neatly closed corrective actions can create an appearance of control while important problems continue unnoticed beneath the surface.
A capable external auditor therefore looks beyond the existence of audit records and asks whether the internal audit process is genuinely providing management with useful intelligence about the health of the organization. Are audit priorities sensible? Are competent auditors being used? Are objective, scope and criteria clear? Are samples adequate for the conclusions reached? Are findings factual? Are significant issues being followed through? Is information from audits being used by management? Most importantly, is the internal audit process contributing to improvement?
This is where practical Lead Auditor training becomes particularly valuable. In TCB’s QMS Lead Auditor Course, learners work with the case of Universal Motors, an automotive service station. Rather than studying internal audit only as a theoretical clause, participants examine how Universal Motors manages its internal audit process. They look at the programme, audit priorities, planning, auditor selection and competence, objectives, scope, criteria, evidence, findings, corrective actions and follow-up, and then determine whether the process itself is effective.
This creates two valuable learning experiences at the same time. The learner begins to understand how an organization should perform its own internal audits, while also learning how an independent external auditor evaluates the organization’s internal audit process. Moving between these two perspectives develops judgement. The learner is no longer merely memorizing Clause 9.2; he or she is learning how Clause 9.2 works inside a living organization.
Auditing competence cannot be created by memorizing clauses alone. An auditor must learn how to ask a meaningful question, listen to an answer, follow a process trail, choose appropriate samples, recognize inconsistencies, distinguish symptoms from systemic weaknesses, evaluate evidence against criteria and communicate conclusions in a respectful and useful manner. A worthwhile Lead Auditor programme should therefore provide opportunities to practice auditing, not merely listen to somebody describing how auditing is done.
The same philosophy influenced my book, Transform Your Life & Business – The ISO Way. I deliberately tried to explain management-system thinking through storytelling rather than presenting ISO merely as a collection of clauses and definitions. Stories allow readers to see how principles operate through people, decisions and everyday organizational situations. They can make technical requirements easier to understand, remember and eventually apply.
Learning need not be confined to the classroom or to hours deliberately reserved for formal study. Modern professional life contains a surprising amount of unavoidable travelling and waiting time. Driving to work, travelling between sites, sitting in airports or undertaking long journeys may be essential for our work, but these hours can otherwise disappear without adding much to our personal development. We may not be able to eliminate that time, but we can sometimes use it differently.
This is where audio learning can be particularly valuable. There are occasions when reading a book is simply impossible, yet listening remains practical. A journey that would otherwise be merely necessary travel can become an opportunity to listen to a professional book, reflect on a management idea or encounter a case study that stimulates new thinking. The objective is not to fill every moment of life with work, but to recognize that some unavoidable time can, when we choose, become useful time for self-development and lifelong learning.
The way audits are conducted has also evolved considerably. An audit no longer necessarily means that every auditor and auditee must be physically present in the same room. Audits can be conducted on-site, remotely or through a blended approach, depending upon the audit objectives, available technology, nature of the activity and associated risks.
Documented information can often be reviewed remotely. Corrective-action evidence may be examined electronically. Interviews can be conducted through video conferencing and other communication technologies. Digital systems and dashboards may be accessed remotely. A follow-up audit may sometimes be completed effectively without travelling to the site.
At other times, physical presence remains essential. An auditor may need to observe equipment, verify actual working conditions, assess housekeeping, observe safety behaviours, follow product flow, inspect infrastructure, witness an activity or obtain evidence that cannot be evaluated adequately from behind a screen. The real question should therefore not be whether an audit should be remote or on-site. The more professional question is: which audit method will provide sufficient reliable evidence to achieve the audit objective?
Technology changes the method, but it does not change the principles. Evidence must remain reliable, confidentiality must be protected, auditors must remain competent, risks associated with the audit method must be considered, and conclusions must remain objective.
There is ultimately a much larger point behind all of this. A management system does exist for business - it does not exist simply because Clause 9.2 has to be satisfied.
An organization was established for a purpose. It needs to deliver that purpose efficiently and profitably. It needs to satisfy customers, protect people, meet applicable obligations, manage its environmental responsibilities, generate sufficient economic value to remain sustainable, employ competent people, maintain healthy suppliers, develop resilient processes, learn from failure, respond to change and continually improve.
An effective internal audit programme gives management an objective view of whether those intentions are being translated into reality. Second-party audits extend the same disciplined thinking to the critical organizations upon which our own performance depends. Together, they help answer two fundamental questions: are we capable of doing what we promise, and are those who serve us capable of helping us deliver that promise to our customers?
That is why I regard internal audit as one of the most valuable processes available to management. A good doctor does not congratulate a patient simply because every medical record is neatly filed. The doctor wants to understand the true condition of the patient. Likewise, a good auditor should not be satisfied because procedures, records and reports look impressive. The auditor seeks to understand the real condition of the management system: what is working, what is weakening, what has changed, where risks are increasing, whether corrective actions are genuinely effective, whether important processes are producing intended results, whether external providers are strengthening or weakening organizational capability, and whether management intent is truly visible at ground zero.
Perhaps the most important question of all is this: what can we learn today that will prevent tomorrow’s failure?
When auditing is approached in this spirit, it stops being a compliance ritual. It becomes a source of organizational intelligence, a mechanism for learning, a safeguard against complacency, a means of strengthening relationships and one of management’s most powerful tools for achieving consistent performance, resilience, continual improvement and sustainable growth.
Internal audit is not about proving that everything is right. It is about having the courage and discipline to discover what is really happening, and then using that knowledge to become better.
Think Beyond the Certificate. Audit to know the truth—not merely to prove conformity.
M S Ray
Author-Auditor and Lead Tutor
TCB Cert.Worldwide LLC
M S Ray
Managing Director and Founder of TCB Cert. Worldwide Group
0 comment