You must conform to the standards.
If the company is not doing so it should be caught by auditors.
The audit is for things you have done or things you failed to do.
Typically you have third party testing done in a lab with proper certification (usually this means GLP).
I use an outside laboratory that’s ISTA certified for package testing. I use their data to write reports that auditors can read.