Cheat sheet

ASQ Certified Quality Auditor Cheat Sheet

Auditing Fundamentals

24.7%of exam

37 Scored ItemsAudit TypesCriteria + RolesEthics + Credibility

Audit Process

30%of exam

45 Scored ItemsPlanningEvidence + FindingsCAPA + Closure

Auditor Competencies

20%of exam

30 Scored ItemsCommunicationInterviewingTeam Dynamics

Program Management + Business

15.3%of exam

23 Scored ItemsProgram MetricsRisk + Electronic RecordsCost of Quality

Quality Tools + Techniques

10%of exam

15 Scored ItemsBasic ToolsStatistics + SamplingV&V + Risk Tools

Quick Facts

Credential
Certified Quality Auditor
CBT Questions
165 multiple-choice
Scored
150 questions
Pretest
15 unscored questions
Exam Time
5 hours 18 minutes
Appointment
5.5 hours
Passing
550/750 scaled
Case Studies
Approximately 10-15%
References
Open book; bound only
Exam Fee
$550 initial
Retake
$350
Experience
Eight years; three decision-making
Recertification
18 RUs every three years
Provider
Prometric

Purpose vs Scope

Purpose

  • Why audit occurs
  • Shapes audit scope

Scope

  • Extent and boundaries
  • Locations, processes, time

Why vs what

Audit Type Picker

  1. Audit own organizationFirst-party audit
  2. Customer audits supplierSecond-party audit
  3. Independent conformity assessmentThird-party audit
  4. Check finished outputProduct audit
  5. Check work executionProcess audit
  6. Check interacting processesSystem audit
  7. Multiple management systemsCombined audit
  8. Multiple auditing organizationsJoint audit
  9. All evidence gathered off-siteRemote audit
  10. Remote plus physical workHybrid audit
  11. Specific serious triggerFor-cause audit
  12. Verify prior actionsCAPA verification audit

Exam Rules

CBT
165 total; 150 scored
Pretest
15 unscored; unidentified
CBT time
318 minutes
PBT
150 scored; five hours
Passing
550 of 750 scaled
Case studies
Approximately 10-15%
Open book
Bound references only
Notes
Must remain bound
Book tabs
Attached before entry
Calculator
Nonprogrammable handheld allowed
Wrong answers
No guessing penalty

Criteria vs Evidence

Criteria

  • Requirement yardstick
  • Standards, contracts, procedures

Evidence

  • Verifiable information
  • Observation, records, interviews

Requirement vs proof

Audit Types

Product audit
Output versus requirements
Process audit
Methods and controls
System audit
Interacting management processes
Desk audit
Documents or questionnaires
Element audit
One requirement across areas
Management audit
Leadership system effectiveness
Combined audit
Multiple management systems
Joint audit
Multiple auditing organizations
Remote audit
ICT without physical presence
Hybrid audit
Remote plus on-site
First-party
Organization audits itself
Second-party
Interested party audits supplier
Third-party
Independent external audit

Second-Party vs Third-Party

Second-party

  • Interested party
  • Commonly customer-supplier

Third-party

  • Independent external body
  • Often certification context

Interested party vs independent

Purpose, Criteria + Roles

Purpose
Why audit occurs
Scope
Extent and boundaries
Criteria
Requirements used as yardstick
Evidence
Verifiable audit information
Finding
Evidence compared with criteria
Compliance audit
Tests specified requirements
Surveillance audit
Confirms continued conformity
For-cause audit
Responds to specific trigger
CAPA verification
Checks implementation and effectiveness
Risk-based audit
Prioritizes higher-risk areas
Audit client
Requests the audit
Auditee
Organization being audited
Lead auditor
Directs audit team
Observer
Watches without interfering
Guide
Facilitates access and safety
Technical expert
Supplies specialized knowledge

Ethics + Credibility

Independence
Freedom from impartiality threats
Objectivity
Unbiased evidence judgment
Due care
Competent professional diligence
Due diligence
Appropriate fact-finding effort
Confidentiality
Protect authorized information
Conflict interest
Disclose and manage promptly
Self-review threat
Auditing own work
Unsafe condition
Escalate promptly
Illegal activity
Use authorized escalation
Qualifications
Knowledge, skill, experience, attributes

Finding Builder: RES

Requirement, Evidence, Statement

R: criteriaE: objective factsS: clear gap

Observation vs Finding

Observation

  • Noted audit condition
  • May need further review

Finding

  • Criteria-linked evaluation
  • Evidence supports conclusion

Noted condition vs evaluation

Evidence-to-Finding Path

  1. Question process operationInterview personnel
  2. Need designed controlReview documents
  3. Need actual practiceObserve work
  4. Claim remains unverifiedCorroborate independently
  5. Evidence seems inconsistentExpand sampling
  6. Evidence lacks requirementFind valid criteria
  7. Criteria remain fulfilledRecord conformity
  8. Criteria not fulfilledWrite nonconformity
  9. No requirement breachedConsider OFI
  10. Facts are disputedReview source evidence
  11. Evidence remains insufficientDocument limitation

Audit Planning

Authority
Permission and access basis
Objectives
Results audit should achieve
Process map
Relationships and boundaries
Prior audits
History and recurring risk
Gap assessment
Potential criteria gaps
Auditor selection
Competence plus independence
Logistics
Access, safety, PPE, workspace
Audit plan
Engagement execution design
Checklist
Coverage guide, not script
Working papers
Evidence and decision trail
Forward tracing
Input toward output
Backward tracing
Outcome toward source
Discovery
Expand around anomalies
Observation
Watch actual work

Correction vs Corrective Action

Correction

  • Fixes detected issue
  • Immediate response

Corrective action

  • Eliminates root cause
  • Prevents recurrence

Fix now vs prevent recurrence

CAPA Verification Path

  1. Immediate impact continuesVerify containment
  2. Problem statement vagueRequest specific scope
  3. Cause lacks evidenceChallenge root cause
  4. Action treats symptomReject CAPA plan
  5. Schedule ignores riskNegotiate milestones
  6. Documents were revisedVerify implementation
  7. Process performance improvedVerify effectiveness
  8. Failure recursReopen CAPA
  9. Commitments remain missedEscalate management
  10. Risk needs fieldworkConduct re-audit
  11. Closure criteria satisfiedClose audit

Performance + Evidence

Opening meeting
Confirm audit arrangements
Interview
Elicits process information
Document review
Checks designed controls
Observation
Checks actual practice
Measurement
Quantifies process evidence
Observed
Directly witnessed
Measured
Quantified with method
Confirmed
Verified against source
Corroborated
Supported independently
Documented
Recorded and traceable
Sufficiency
Enough evidence volume
Reliability
Trustworthy evidence source
Closing meeting
Present results and next steps
Factual concurrence
Agreement on evidence facts

Implementation vs Effectiveness

Implementation

  • Action completed
  • Procedure and training evidence

Effectiveness

  • Failure stays controlled
  • Performance evidence over time

Done vs works

Reporting + CAPA

Nonconformity
Requirement not fulfilled
Observation
Not automatically nonconformity
OFI
Nonmandatory improvement opportunity
Unique ID
Enables finding tracking
Executive summary
Prioritized management view
Report approval
Confirms technical completeness
Distribution
Authorized recipients only
Audit file
Complete defensible record
Correction
Fixes immediate nonconformity
Containment
Controls immediate impact
Corrective action
Prevents recurrence
Preventive action
Prevents potential occurrence
Root cause
System cause explaining evidence
Implementation check
Action completed as planned
Effectiveness check
Failure mode remains controlled
Ineffective CAPA
Escalate, reissue, or re-audit
Audit closure
Program criteria satisfied

Team Stages: FSNPA

Form, Storm, Norm, Perform, Adjourn

Form: orientStorm: conflictNorm: alignPerform: deliverAdjourn: close

Open vs Closed Questions

Open

  • Explores process detail
  • How, what, describe

Closed

  • Confirms specific fact
  • Yes, no, exact value

Explore vs confirm

Interviewing + Conflict

Open question
Explores process detail
Closed question
Confirms specific fact
Leading question
Suggests desired answer
Active listening
Attend, clarify, summarize
Paraphrasing
Confirms shared meaning
Empathy
Supports respectful disclosure
Nonverbal cue
Prompt verification, not assumption
Translator
Manage fidelity risk
Supervisor present
Watch coaching pressure
Mild conflict
Clarify facts and criteria
Severe disruption
Reset rules or escalate
Cool-down
Pause unproductive escalation

Team + Communication

Diplomacy
Protects working relationship
Cultural awareness
Adapts communication respectfully
Problem-solving
Resolves live constraints
Attention detail
Strengthens evidence accuracy
Negotiation
Lead auditor skill
Forming
Roles remain uncertain
Storming
Conflict surfaces
Norming
Team standards stabilize
Performing
Team works effectively
Adjourning
Closeout and lessons
Written channel
Precise permanent record
Oral channel
Immediate clarification
Electronic channel
Fast; confidentiality controls

COQ: PAIF

Prevention, Appraisal, Internal failure, External failure

P: preventA: assessI: before deliveryE: after delivery

Audit Program Management

Management support
Authority, independence, resources
Staffing budget
Plan, conduct, respond time
Auditor training
Maintains relevant competence
Program metric
Measures value and risk
Internal program
Policies, schedules, review cycles
Supplier program
Qualification through improvement
Self-assessment
Supplier evidence needing verification
Surveillance
Ongoing supplier monitoring
Best practice
Proven transferable method
Risk-based schedule
Risk sets frequency and depth
Management review
Trends and risk input
Business continuity
Critical operations survive disruption
Succession planning
Protects critical-role continuity

Business + Electronic Records

Data integrity
Complete trustworthy records
Access control
Authorized system use
Audit trail
Who changed what when
Retention
Records remain available
Cybersecurity
Protect systems and evidence
Prevention cost
Avoids quality failures
Appraisal cost
Evaluates conformity
Internal failure
Failure before delivery
External failure
Failure after delivery
Process interrelationship
Handoffs create shared risk
Strategic deployment
Audit tests execution

DMAIC

Define, Measure, Analyze, Improve, Control

D: problemM: baselineA: causesI: solutionsC: sustain

Common vs Special Cause

Common cause

  • Inherent system variation
  • Needs system change

Special cause

  • Assignable unusual variation
  • Investigate specific source

System noise vs signal

Quality Tool Picker

  1. Rank defect categoriesPareto chart
  2. Brainstorm possible causesFishbone diagram
  3. Map process sequenceFlowchart
  4. Collect occurrence talliesCheck sheet
  5. View distribution shapeHistogram
  6. Compare two variablesScatter diagram
  7. Monitor process stabilityControl chart
  8. Probe underlying cause5 Whys
  9. Structure improvement projectDMAIC
  10. Organize workplace5S
  11. Map end-to-end flowValue-stream map
  12. Prioritize failure modesFMEA
  13. Analyze strategic contextSWOT

Basic Quality Tools

Pareto chart
Ranks vital few
Fishbone
Organizes potential causes
Flowchart
Maps process sequence
Control chart
Monitors process stability
Check sheet
Collects structured tallies
Scatter diagram
Shows variable association
Histogram
Shows distribution shape
5 Whys
Drills toward root cause
PDCA
Closes improvement loop
DMAIC
Structured process improvement
5S
Organizes visual workplace
Kanban
Downstream pull signal
Poka-yoke
Prevents or detects errors
Value-stream map
Exposes flow and delay

5S

Sort, Set, Shine, Standardize, Sustain

Sort: removeSet: arrangeShine: cleanStandardize: repeatSustain: maintain

Control vs Specification Limits

Control limits

  • Calculated from process
  • Signals statistical stability

Specification limits

  • Set by requirements
  • Defines acceptable output

Behavior vs requirement

Sampling Picker

  1. Need unbiased selectionRandom sampling
  2. Distinct subgroups matterStratified sampling
  3. Natural groups dominateCluster sampling
  4. Critical risk dominatesRisk-based sampling
  5. Data are pass-failAttributes plan
  6. Data are measurementsVariables plan
  7. Measurement trust uncertainPerform MSA
  8. Lot disposition neededAcceptance sampling

Statistics + Variation

Mean
Arithmetic average; outlier-sensitive
Median
Ordered middle; outlier-resistant
Mode
Most frequent value
Standard deviation
Spread around mean
Frequency distribution
Counts across value ranges
Common cause
Inherent system variation
Special cause
Assignable unusual variation
Control limits
Calculated process behavior
Specification limits
Customer or engineering requirements
Cp
Potential spread capability
Cpk
Centered actual capability
Cp formula
(USL−LSL) ÷ 6σ
Cpk formula
Nearest spec distance ÷ 3σ
Outlier
Investigate before excluding

Eight Wastes: DOWNTIME

Defects, Overproduction, Waiting, Talent, Transport, Inventory, Motion, Extra

D: defectsO: overproductionW: waitingN: nonused talentT: transportI: inventoryM: motionE: extra processing

Cp vs Cpk

Cp

  • Potential capability
  • Spread only

Cpk

  • Actual capability
  • Spread plus centering

Potential vs actual

Sampling, Risk + V&V

Attribute sampling
Pass-fail or defect counts
Variables sampling
Measured continuous data
Random sample
Equal selection chance
Stratified sample
Samples every subgroup
Cluster sample
Samples natural groups
Risk-based sample
Targets higher-risk evidence
Consumer risk β
Accepting unacceptable lot
Producer risk α
Rejecting acceptable lot
Confidence level
Statistical assurance degree
MSA
Measurement system adequacy
Change control
Controls approved changes
Configuration management
Maintains approved baselines
Verification
Meets specified requirements
Validation
Meets intended use
FMEA
Prioritizes potential failure modes
HACCP
Controls critical hazard points
CTQ
Measurable customer-critical requirement
SWOT
Internal and external context

Verification vs Validation

Verification

  • Requirements met
  • Built right

Validation

  • Intended use met
  • Right thing built

Specification vs user need

Consumer vs Producer Risk

Consumer risk β

  • Accept bad lot
  • False acceptance

Producer risk α

  • Reject good lot
  • False rejection

Buyer harm vs seller harm

Common Traps

Scaled score

550 of 750 scaled Not 73.3% correct

CBT item count

165 total questions Only 150 are scored

Pretest items

Unidentified throughout exam Answer every question

Open book

Bound references allowed Loose notes prohibited

Audit client

Requests the audit May differ from auditee

Party relationship

Certification service contract Customer-supplier relationship

Checklist use

Supports coverage consistency Never replaces judgment

Objective evidence

Must be verifiable Documented does not ensure truth

OFI classification

No requirement breach Not hidden nonconformity

CAPA ownership

Auditee designs action Auditor evaluates adequacy

CAPA closure

Implementation plus effectiveness Procedure update alone insufficient

Control limits

Describe process behavior Do not define acceptance

Process capability

Requires stable process High Cp alone insufficient

Scatter diagrams

Show association Do not prove causation

Outlier handling

Investigate before exclusion Never delete automatically

Last Minute

  1. 1.I-V weights: 24.7%,30%,20%,15.3%,10%
  2. 2.Audit Process carries 45 items
  3. 3.CBT: 150 scored plus 15 pretest
  4. 4.Passing score: 550/750 scaled
  5. 5.Case studies: approximately 10-15%
  6. 6.All reference materials stay bound
  7. 7.Purpose explains why; scope sets boundaries
  8. 8.Criteria = requirement; evidence = proof
  9. 9.Finding compares evidence with criteria
  10. 10.First-party = internal self-audit
  11. 11.Second-party = interested-party audit
  12. 12.Third-party = independent external audit
  13. 13.Forward traces input toward output
  14. 14.Backward traces outcome toward source
  15. 15.Corroborate high-risk disputed evidence
  16. 16.Correction fixes; corrective action prevents recurrence
  17. 17.CAPA needs implementation and effectiveness
  18. 18.Open questions explore; closed confirm
  19. 19.COQ: prevention, appraisal, two failures
  20. 20.Control limits differ from specifications
  21. 21.Cp = spread; Cpk includes centering
  22. 22.Consumer risk accepts bad lots
  23. 23.Producer risk rejects good lots
  24. 24.Verification = requirements; validation = use
  25. 25.Investigate every outlier before exclusion
Same family resources

Explore More ASQ Quality Certifications

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.