Cheat sheet

ASQ Certified Quality Auditor Cheat Sheet

Auditing Fundamentals

24.7%of exam

37 Scored ItemsAudit TypesCriteria + RolesEthics + Credibility

Audit Process

30%of exam

45 Scored ItemsPlanningEvidence + FindingsCAPA + Closure

Auditor Competencies

20%of exam

30 Scored ItemsCommunicationInterviewingTeam Dynamics

Program Management + Business

15.3%of exam

23 Scored ItemsProgram MetricsRisk + Electronic RecordsCost of Quality

Quality Tools + Techniques

10%of exam

15 Scored ItemsBasic ToolsStatistics + SamplingV&V + Risk Tools

Quick Facts

Credential
Certified Quality Auditor
CBT Questions
165 multiple-choice
Scored
150 questions
Pretest
15 unscored questions
Exam Time
5 hours 18 minutes
Appointment
5.5 hours
Passing
550/750 scaled
Case Studies
Approximately 10-15%
References
Open book; bound only
Exam Fee
$550 initial
Retake
$350
Experience
Eight years; three decision-making
Recertification
18 RUs every three years
Provider
Prometric

Purpose vs Scope

Purpose

  • Why audit occurs
  • Shapes audit scope

Scope

  • Extent and boundaries
  • Locations, processes, time

Why vs what

Audit Type Picker

  1. Audit own organization→First-party audit
  2. Customer audits supplier→Second-party audit
  3. Independent conformity assessment→Third-party audit
  4. Check finished output→Product audit
  5. Check work execution→Process audit
  6. Check interacting processes→System audit
  7. Multiple management systems→Combined audit
  8. Multiple auditing organizations→Joint audit
  9. All evidence gathered off-site→Remote audit
  10. Remote plus physical work→Hybrid audit
  11. Specific serious trigger→For-cause audit
  12. Verify prior actions→CAPA verification audit

Exam Rules

CBT
165 total; 150 scored
Pretest
15 unscored; unidentified
CBT time
318 minutes
PBT
150 scored; five hours
Passing
550 of 750 scaled
Case studies
Approximately 10-15%
Open book
Bound references only
Notes
Must remain bound
Book tabs
Attached before entry
Calculator
Nonprogrammable handheld allowed
Wrong answers
No guessing penalty

Criteria vs Evidence

Criteria

  • Requirement yardstick
  • Standards, contracts, procedures

Evidence

  • Verifiable information
  • Observation, records, interviews

Requirement vs proof

Audit Types

Product audit
Output versus requirements
Process audit
Methods and controls
System audit
Interacting management processes
Desk audit
Documents or questionnaires
Element audit
One requirement across areas
Management audit
Leadership system effectiveness
Combined audit
Multiple management systems
Joint audit
Multiple auditing organizations
Remote audit
ICT without physical presence
Hybrid audit
Remote plus on-site
First-party
Organization audits itself
Second-party
Interested party audits supplier
Third-party
Independent external audit

Second-Party vs Third-Party

Second-party

  • Interested party
  • Commonly customer-supplier

Third-party

  • Independent external body
  • Often certification context

Interested party vs independent

Purpose, Criteria + Roles

Purpose
Why audit occurs
Scope
Extent and boundaries
Criteria
Requirements used as yardstick
Evidence
Verifiable audit information
Finding
Evidence compared with criteria
Compliance audit
Tests specified requirements
Surveillance audit
Confirms continued conformity
For-cause audit
Responds to specific trigger
CAPA verification
Checks implementation and effectiveness
Risk-based audit
Prioritizes higher-risk areas
Audit client
Requests the audit
Auditee
Organization being audited
Lead auditor
Directs audit team
Observer
Watches without interfering
Guide
Facilitates access and safety
Technical expert
Supplies specialized knowledge

Ethics + Credibility

Independence
Freedom from impartiality threats
Objectivity
Unbiased evidence judgment
Due care
Competent professional diligence
Due diligence
Appropriate fact-finding effort
Confidentiality
Protect authorized information
Conflict interest
Disclose and manage promptly
Self-review threat
Auditing own work
Unsafe condition
Escalate promptly
Illegal activity
Use authorized escalation
Qualifications
Knowledge, skill, experience, attributes

Finding Builder: RES

Requirement, Evidence, Statement

R: criteriaE: objective factsS: clear gap

Observation vs Finding

Observation

  • Noted audit condition
  • May need further review

Finding

  • Criteria-linked evaluation
  • Evidence supports conclusion

Noted condition vs evaluation

Evidence-to-Finding Path

  1. Question process operation→Interview personnel
  2. Need designed control→Review documents
  3. Need actual practice→Observe work
  4. Claim remains unverified→Corroborate independently
  5. Evidence seems inconsistent→Expand sampling
  6. Evidence lacks requirement→Find valid criteria
  7. Criteria remain fulfilled→Record conformity
  8. Criteria not fulfilled→Write nonconformity
  9. No requirement breached→Consider OFI
  10. Facts are disputed→Review source evidence
  11. Evidence remains insufficient→Document limitation

Audit Planning

Authority
Permission and access basis
Objectives
Results audit should achieve
Process map
Relationships and boundaries
Prior audits
History and recurring risk
Gap assessment
Potential criteria gaps
Auditor selection
Competence plus independence
Logistics
Access, safety, PPE, workspace
Audit plan
Engagement execution design
Checklist
Coverage guide, not script
Working papers
Evidence and decision trail
Forward tracing
Input toward output
Backward tracing
Outcome toward source
Discovery
Expand around anomalies
Observation
Watch actual work

Correction vs Corrective Action

Correction

  • Fixes detected issue
  • Immediate response

Corrective action

  • Eliminates root cause
  • Prevents recurrence

Fix now vs prevent recurrence

CAPA Verification Path

  1. Immediate impact continues→Verify containment
  2. Problem statement vague→Request specific scope
  3. Cause lacks evidence→Challenge root cause
  4. Action treats symptom→Reject CAPA plan
  5. Schedule ignores risk→Negotiate milestones
  6. Documents were revised→Verify implementation
  7. Process performance improved→Verify effectiveness
  8. Failure recurs→Reopen CAPA
  9. Commitments remain missed→Escalate management
  10. Risk needs fieldwork→Conduct re-audit
  11. Closure criteria satisfied→Close audit

Performance + Evidence

Opening meeting
Confirm audit arrangements
Interview
Elicits process information
Document review
Checks designed controls
Observation
Checks actual practice
Measurement
Quantifies process evidence
Observed
Directly witnessed
Measured
Quantified with method
Confirmed
Verified against source
Corroborated
Supported independently
Documented
Recorded and traceable
Sufficiency
Enough evidence volume
Reliability
Trustworthy evidence source
Closing meeting
Present results and next steps
Factual concurrence
Agreement on evidence facts

Implementation vs Effectiveness

Implementation

  • Action completed
  • Procedure and training evidence

Effectiveness

  • Failure stays controlled
  • Performance evidence over time

Done vs works

Reporting + CAPA

Nonconformity
Requirement not fulfilled
Observation
Not automatically nonconformity
OFI
Nonmandatory improvement opportunity
Unique ID
Enables finding tracking
Executive summary
Prioritized management view
Report approval
Confirms technical completeness
Distribution
Authorized recipients only
Audit file
Complete defensible record
Correction
Fixes immediate nonconformity
Containment
Controls immediate impact
Corrective action
Prevents recurrence
Preventive action
Prevents potential occurrence
Root cause
System cause explaining evidence
Implementation check
Action completed as planned
Effectiveness check
Failure mode remains controlled
Ineffective CAPA
Escalate, reissue, or re-audit
Audit closure
Program criteria satisfied

Team Stages: FSNPA

Form, Storm, Norm, Perform, Adjourn

Form: orientStorm: conflictNorm: alignPerform: deliverAdjourn: close

Open vs Closed Questions

Open

  • Explores process detail
  • How, what, describe

Closed

  • Confirms specific fact
  • Yes, no, exact value

Explore vs confirm

Interviewing + Conflict

Open question
Explores process detail
Closed question
Confirms specific fact
Leading question
Suggests desired answer
Active listening
Attend, clarify, summarize
Paraphrasing
Confirms shared meaning
Empathy
Supports respectful disclosure
Nonverbal cue
Prompt verification, not assumption
Translator
Manage fidelity risk
Supervisor present
Watch coaching pressure
Mild conflict
Clarify facts and criteria
Severe disruption
Reset rules or escalate
Cool-down
Pause unproductive escalation

Team + Communication

Diplomacy
Protects working relationship
Cultural awareness
Adapts communication respectfully
Problem-solving
Resolves live constraints
Attention detail
Strengthens evidence accuracy
Negotiation
Lead auditor skill
Forming
Roles remain uncertain
Storming
Conflict surfaces
Norming
Team standards stabilize
Performing
Team works effectively
Adjourning
Closeout and lessons
Written channel
Precise permanent record
Oral channel
Immediate clarification
Electronic channel
Fast; confidentiality controls

COQ: PAIF

Prevention, Appraisal, Internal failure, External failure

P: preventA: assessI: before deliveryE: after delivery

Audit Program Management

Management support
Authority, independence, resources
Staffing budget
Plan, conduct, respond time
Auditor training
Maintains relevant competence
Program metric
Measures value and risk
Internal program
Policies, schedules, review cycles
Supplier program
Qualification through improvement
Self-assessment
Supplier evidence needing verification
Surveillance
Ongoing supplier monitoring
Best practice
Proven transferable method
Risk-based schedule
Risk sets frequency and depth
Management review
Trends and risk input
Business continuity
Critical operations survive disruption
Succession planning
Protects critical-role continuity

Business + Electronic Records

Data integrity
Complete trustworthy records
Access control
Authorized system use
Audit trail
Who changed what when
Retention
Records remain available
Cybersecurity
Protect systems and evidence
Prevention cost
Avoids quality failures
Appraisal cost
Evaluates conformity
Internal failure
Failure before delivery
External failure
Failure after delivery
Process interrelationship
Handoffs create shared risk
Strategic deployment
Audit tests execution

DMAIC

Define, Measure, Analyze, Improve, Control

D: problemM: baselineA: causesI: solutionsC: sustain

Common vs Special Cause

Common cause

  • Inherent system variation
  • Needs system change

Special cause

  • Assignable unusual variation
  • Investigate specific source

System noise vs signal

Quality Tool Picker

  1. Rank defect categories→Pareto chart
  2. Brainstorm possible causes→Fishbone diagram
  3. Map process sequence→Flowchart
  4. Collect occurrence tallies→Check sheet
  5. View distribution shape→Histogram
  6. Compare two variables→Scatter diagram
  7. Monitor process stability→Control chart
  8. Probe underlying cause→5 Whys
  9. Structure improvement project→DMAIC
  10. Organize workplace→5S
  11. Map end-to-end flow→Value-stream map
  12. Prioritize failure modes→FMEA
  13. Analyze strategic context→SWOT

Basic Quality Tools

Pareto chart
Ranks vital few
Fishbone
Organizes potential causes
Flowchart
Maps process sequence
Control chart
Monitors process stability
Check sheet
Collects structured tallies
Scatter diagram
Shows variable association
Histogram
Shows distribution shape
5 Whys
Drills toward root cause
PDCA
Closes improvement loop
DMAIC
Structured process improvement
5S
Organizes visual workplace
Kanban
Downstream pull signal
Poka-yoke
Prevents or detects errors
Value-stream map
Exposes flow and delay

5S

Sort, Set, Shine, Standardize, Sustain

Sort: removeSet: arrangeShine: cleanStandardize: repeatSustain: maintain

Control vs Specification Limits

Control limits

  • Calculated from process
  • Signals statistical stability

Specification limits

  • Set by requirements
  • Defines acceptable output

Behavior vs requirement

Sampling Picker

  1. Need unbiased selection→Random sampling
  2. Distinct subgroups matter→Stratified sampling
  3. Natural groups dominate→Cluster sampling
  4. Critical risk dominates→Risk-based sampling
  5. Data are pass-fail→Attributes plan
  6. Data are measurements→Variables plan
  7. Measurement trust uncertain→Perform MSA
  8. Lot disposition needed→Acceptance sampling

Statistics + Variation

Mean
Arithmetic average; outlier-sensitive
Median
Ordered middle; outlier-resistant
Mode
Most frequent value
Standard deviation
Spread around mean
Frequency distribution
Counts across value ranges
Common cause
Inherent system variation
Special cause
Assignable unusual variation
Control limits
Calculated process behavior
Specification limits
Customer or engineering requirements
Cp
Potential spread capability
Cpk
Centered actual capability
Cp formula
(USL−LSL) ÷ 6σ
Cpk formula
Nearest spec distance ÷ 3σ
Outlier
Investigate before excluding

Eight Wastes: DOWNTIME

Defects, Overproduction, Waiting, Talent, Transport, Inventory, Motion, Extra

D: defectsO: overproductionW: waitingN: nonused talentT: transportI: inventoryM: motionE: extra processing

Cp vs Cpk

Cp

  • Potential capability
  • Spread only

Cpk

  • Actual capability
  • Spread plus centering

Potential vs actual

Sampling, Risk + V&V

Attribute sampling
Pass-fail or defect counts
Variables sampling
Measured continuous data
Random sample
Equal selection chance
Stratified sample
Samples every subgroup
Cluster sample
Samples natural groups
Risk-based sample
Targets higher-risk evidence
Consumer risk β
Accepting unacceptable lot
Producer risk α
Rejecting acceptable lot
Confidence level
Statistical assurance degree
MSA
Measurement system adequacy
Change control
Controls approved changes
Configuration management
Maintains approved baselines
Verification
Meets specified requirements
Validation
Meets intended use
FMEA
Prioritizes potential failure modes
HACCP
Controls critical hazard points
CTQ
Measurable customer-critical requirement
SWOT
Internal and external context

Verification vs Validation

Verification

  • Requirements met
  • Built right

Validation

  • Intended use met
  • Right thing built

Specification vs user need

Consumer vs Producer Risk

Consumer risk β

  • Accept bad lot
  • False acceptance

Producer risk α

  • Reject good lot
  • False rejection

Buyer harm vs seller harm

Common Traps

Scaled score

550 of 750 scaled ≠ Not 73.3% correct

CBT item count

165 total questions ≠ Only 150 are scored

Pretest items

Unidentified throughout exam ≠ Answer every question

Open book

Bound references allowed ≠ Loose notes prohibited

Audit client

Requests the audit ≠ May differ from auditee

Party relationship

Certification service contract ≠ Customer-supplier relationship

Checklist use

Supports coverage consistency ≠ Never replaces judgment

Objective evidence

Must be verifiable ≠ Documented does not ensure truth

OFI classification

No requirement breach ≠ Not hidden nonconformity

CAPA ownership

Auditee designs action ≠ Auditor evaluates adequacy

CAPA closure

Implementation plus effectiveness ≠ Procedure update alone insufficient

Control limits

Describe process behavior ≠ Do not define acceptance

Process capability

Requires stable process ≠ High Cp alone insufficient

Scatter diagrams

Show association ≠ Do not prove causation

Outlier handling

Investigate before exclusion ≠ Never delete automatically

Last Minute

  1. 1.I-V weights: 24.7%,30%,20%,15.3%,10%
  2. 2.Audit Process carries 45 items
  3. 3.CBT: 150 scored plus 15 pretest
  4. 4.Passing score: 550/750 scaled
  5. 5.Case studies: approximately 10-15%
  6. 6.All reference materials stay bound
  7. 7.Purpose explains why; scope sets boundaries
  8. 8.Criteria = requirement; evidence = proof
  9. 9.Finding compares evidence with criteria
  10. 10.First-party = internal self-audit
  11. 11.Second-party = interested-party audit
  12. 12.Third-party = independent external audit
  13. 13.Forward traces input toward output
  14. 14.Backward traces outcome toward source
  15. 15.Corroborate high-risk disputed evidence
  16. 16.Correction fixes; corrective action prevents recurrence
  17. 17.CAPA needs implementation and effectiveness
  18. 18.Open questions explore; closed confirm
  19. 19.COQ: prevention, appraisal, two failures
  20. 20.Control limits differ from specifications
  21. 21.Cp = spread; Cpk includes centering
  22. 22.Consumer risk accepts bad lots
  23. 23.Producer risk rejects good lots
  24. 24.Verification = requirements; validation = use
  25. 25.Investigate every outlier before exclusion
Same family resources

Explore More ASQ Quality Certifications

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.