Free CQA Exam Flashcards
Memorize 50 essential terms and definitions for the ASQ Certified Quality Auditor. See the term, recall the definition, then flip to check yourself.
How do first-, second-, and third-party audits differ?
A first-party audit is performed within an organization on its own system or processes. A second-party audit is performed by a party with an interest, commonly a customer auditing a supplier. A third-party audit is performed by an independent external body, such as a certification body.
Filter by Topic
Jump to Card
About These CQA Flashcards
These 50 flashcards are designed to help you memorize key terms and definitions for the ASQ Certified Quality Auditor. Each card shows a term on the front and its definition on the back—the classic flashcard format for vocabulary memorization. Use these alongside our practice questions to build both recall and comprehension.
Topics Covered
Complete Flashcard Reference
Review every term in this set. Open any term to reveal its definition.
How do first-, second-, and third-party audits differ?
A first-party audit is performed within an organization on its own system or processes. A second-party audit is performed by a party with an interest, commonly a customer auditing a supplier. A third-party audit is performed by an independent external body, such as a certification body.
What distinguishes product, process, and system audits?
A product audit evaluates an output against product requirements. A process audit evaluates whether a process is controlled and effective. A system audit evaluates an interconnected management system against broader criteria. The audit object—not merely the department visited—determines the type.
How do combined, joint, hybrid, and remote audits differ?
A combined audit evaluates multiple management systems together. A joint audit uses two or more auditing organizations on one auditee. A hybrid audit mixes on-site and remote methods, while a remote audit gathers evidence without the audit team being physically present at the audited location.
When are compliance, surveillance, and for-cause audits used?
A compliance audit determines conformity with specified requirements. A surveillance audit periodically checks continued conformity after approval or certification. A for-cause audit responds to a specific concern, event, or credible signal and focuses its scope on the triggering risk.
How should an audit's purpose influence its scope?
The purpose explains why the audit is being performed; the scope defines its boundaries, locations, functions, processes, and period. A CAPA-verification audit may be narrow and evidence-focused, while a system-effectiveness audit requires broader process interactions. Scope should be sufficient to achieve the stated purpose.
How are audit criteria, evidence, and findings related?
Criteria are the requirements used as the reference. Evidence is verifiable information gathered during the audit. A finding results from evaluating that evidence against the criteria. Without a criterion, an observation may be interesting but cannot support a conformity or nonconformity conclusion.
What is the difference between the audit client and the auditee?
The audit client is the person or organization requesting or commissioning the audit. The auditee is the organization or part of an organization being audited. They may be within the same company, but their roles, authority, and responsibilities should remain clear.
What responsibility makes the lead auditor different from other team members?
The lead auditor directs the team and is accountable for coordinating planning, assignments, communication, evidence evaluation, meetings, and the report. Team members gather and analyze evidence in assigned areas. The lead should use team expertise without surrendering responsibility for a coherent audit conclusion.
What should an observer do during an audit?
An observer accompanies the audit under agreed arrangements but does not perform auditor duties or interfere with evidence collection. The lead auditor should clarify the observer's role, confidentiality obligations, and access limits so the observer does not influence interviews or conclusions.
How do confidentiality, due care, and conflict-of-interest controls support ethical auditing?
Confidentiality protects information obtained through the audit. Due care requires competent, diligent judgment proportional to the risk. Conflict-of-interest controls identify relationships or incentives that could impair impartiality. An auditor should disclose a conflict and follow the program's decision on reassignment or safeguards.
What should an auditor do after encountering credible evidence of an illegal or unsafe condition?
If immediate danger exists, follow the site's emergency and safety procedures. Preserve and verify the evidence, then communicate promptly through the authorized escalation path. Stay within the auditor's authority and applicable legal obligations; do not conceal the issue or make accusations beyond the evidence.
Which factors make an audit conclusion credible?
Credibility depends on competent auditors, objective and traceable evidence, consistent methods, transparent criteria, and sufficient independence from the activity audited. Independence does not require every auditor to be external; an internal auditor can be independent of the work being evaluated.
Which decisions must be settled at the start of audit planning?
Confirm audit authority, purpose, scope, type, delivery format, applicable criteria, process boundaries, resources, and documentation needs. These decisions should agree with one another. A scope that cannot answer the audit purpose should be corrected before detailed scheduling begins.
Which pre-audit information is most useful for risk-focused planning?
Review applicable requirements, process maps, procedures, prior audit results, complaints, performance trends, major changes, and open CAPAs. Look for repeat findings, high-risk interfaces, and weak performance. Pre-audit review directs attention but does not replace collecting current evidence.
What makes an audit sampling plan defensible?
Define the population, selection method, sample rationale, and how risk affects depth. Include different shifts, sites, products, periods, or risk groups when relevant. Record what was sampled so another reviewer can understand the coverage and limits of the evidence.
How do forward and backward tracing work in an audit?
Forward tracing follows an input or requirement through processing to the final output and records. Backward tracing starts with an output, event, or record and follows it to source materials, approvals, and prior steps. Using both directions can expose broken traceability or inconsistent controls.
What should a practical audit plan communicate?
It should identify objectives, scope, criteria, locations, timing, team assignments, key contacts, meetings, methods, and logistical or confidentiality needs. Share it with relevant stakeholders early enough to resolve conflicts, while recognizing that evidence may justify controlled changes during the audit.
What is the purpose of the opening meeting?
Confirm authority, purpose, scope, criteria, schedule, methods, communication channels, rating approach, confidentiality, safety, and participant roles. The meeting creates a common operating framework; it is not the time to announce conclusions before evidence has been collected.
Why should auditors triangulate interviews, observation, measurements, and documents?
Each method has limits. Interviews describe intended or remembered practice, observation shows current behavior, measurements provide quantitative facts, and documents show requirements or records. Agreement among independent sources strengthens evidence; contradictions indicate where further investigation is needed.
What characteristics distinguish objective evidence from an assumption?
Objective evidence can be observed, measured, confirmed, corroborated, or documented. It is specific enough to be verified and connected to the audit criteria. An auditor's intuition may guide the next sample, but it is not itself evidence for a finding.
When should the lead auditor adjust the plan during fieldwork?
Adjust when evidence reveals unexpected risk, a key process is unavailable, time is being consumed unevenly, or the original coverage will not achieve the objectives. Reallocate resources and communicate the change promptly while protecting scope integrity and required independence.
How should audit evidence be organized for evaluation?
Group related evidence by criterion and process, then consider significance, severity, frequency, and risk. Distinguish an isolated event from a systemic pattern and assess potential effects on products, processes, systems, and cost. Escalate sampling when the available evidence is insufficient.
What must be achieved in the closing meeting?
Restate purpose, scope, and rating criteria; present supported results; confirm that the evidence is understood; and explain response, CAPA, follow-up, and responsibility expectations. Agreement on the evidence is valuable, but the auditee need not agree with every audit conclusion.
What three elements make a strong nonconformity statement?
Identify the applicable requirement, state the specific objective evidence, and explain the gap between them. Avoid blame, speculation, and vague phrases such as 'poor system.' A reader should be able to trace the statement to both the criterion and the sampled facts.
What makes an audit report actionable?
Provide context, objectives, scope, criteria, methods, a clear executive summary, prioritized findings, evidence-based conclusions, and response timelines. Use unique identifiers for tracking and obtain required approvals before controlled distribution and retention of the audit file.
How do correction, root cause, and corrective action differ?
Correction fixes or contains the detected problem. Root-cause analysis determines why the problem occurred. Corrective action removes or controls the cause to prevent recurrence. Closing a finding after correction alone leaves the system vulnerable to the same failure.
What evidence supports CAPA effectiveness and audit closure?
Verify implementation through revised documents, records, training, and direct observation, then examine outcome data over a meaningful period to determine whether recurrence was prevented. If action is late or ineffective, escalate, reissue the request, expand follow-up, or re-audit under the program rules.
Which personal characteristics make an auditor effective?
Useful characteristics include integrity, observation, analytical thinking, attention to detail, diplomacy, cultural awareness, adaptability, and the ability to work independently and collaboratively. Effective auditors remain curious and firm without becoming adversarial or assuming that difference equals nonconformity.
How should a lead auditor assign work across the team?
Match assignments to competence, technical expertise, independence, language ability, and risk while balancing workload and schedule. Clarify deliverables and interfaces, especially where processes cross departments. Reassign resources when evidence or timing shows the original plan is no longer effective.
How should an auditor respond to delaying tactics or repeated interruptions?
Remain calm, restate the request and agreed ground rules, clarify why the evidence is needed, and offer a reasonable time-bound path. If obstruction continues, document it and involve the lead auditor, audit client, or appropriate authority rather than arguing personally.
How should audit communication change for technical and executive audiences?
Technical audiences may need detailed evidence, process data, and criterion references. Executives need material risk, trends, business impact, and decisions. Keep the facts consistent while changing depth and presentation; charts should clarify the conclusion rather than decorate the report.
When should an auditor use open-ended versus closed questions?
Use open-ended questions to explore a process: 'How do you approve this change?' Use closed questions to confirm a specific fact: 'Was this approved before release?' Begin broadly, then narrow and verify without using leading questions that suggest the desired answer.
How do active listening and paraphrasing improve an interview?
Active listening focuses on the speaker, pauses, and meaning rather than preparing the next question. Paraphrasing—'So the supervisor releases every batch; is that correct?'—checks understanding and gives the interviewee a chance to correct ambiguity before the auditor records evidence.
What should an auditor consider when a supervisor or translator joins an interview?
A supervisor may inhibit candid responses, while a translator can alter nuance. Explain roles, direct questions to the interviewee, observe pauses and body language carefully, and confirm key facts through records or observation. Use private interviews when appropriate and permitted.
What are the stages of team development?
Forming establishes orientation and dependence; storming brings disagreement; norming establishes working agreements; performing delivers effective collaboration; and adjourning closes the team's work. A leader changes support and direction as the team moves through these stages.
How does facilitation protect an audit team's objectivity?
Invite evidence and interpretations from every member, separate facts from opinions, test conclusions against criteria, and resolve disagreement through reasoned review. Prevent one expert or senior member from dominating. Consensus should result from evidence, not pressure to appear united.
What communication controls are especially important in remote or multisite audits?
Define secure platforms, time zones, contacts, document access, evidence naming, backup channels, and when live video or local support is required. Confirm what was actually observed versus shown indirectly. Geographic convenience must not weaken evidence integrity or confidentiality.
What senior-management support does an effective audit program require?
Management should establish authority, independence, objectives, resources, and access, then respond to material results. Budgets must include planning, fieldwork, reporting, follow-up, auditee time, and special audit needs. A nominal program without time or escalation authority cannot provide credible assurance.
How should an audit program maintain auditor competence?
Define role-specific knowledge and skill requirements, evaluate initial competence, provide training in audit methods and applicable requirements, observe performance, and maintain continuing development. Include cultural, communication, facilitation, and industry considerations rather than treating one generic course as permanent qualification.
Which metrics reveal whether an audit program is effective?
Use a balanced set such as plan completion, report timeliness, CAPA closure and effectiveness, repeat findings, risk reduction, stakeholder response, and business impact. Counts of completed audits show activity, not effectiveness. Summarize trends and changing risks for management review.
How should an internal audit schedule respond to trends?
Set a risk-based cycle, then revise frequency and scope using changes, prior results, complaints, performance, and emerging risks. Analyze findings across departments and sites for systemic patterns. Share verified best practices rather than merely repeating the same calendar each year.
What belongs in an external supplier-audit program?
Define risk-based qualification, self-assessment, audit, surveillance, improvement, escalation, and re-evaluation methods. Consider supplier criticality, performance, geography, outsourced-audit controls, and contractual access. A questionnaire alone is not sufficient assurance for every supplier risk.
How does organizational risk affect audit frequency and scope?
Higher or changing risk can justify more frequent, deeper, or specially skilled audits; stable low risk may support reduced coverage with monitoring. Consider business continuity and succession readiness as well as operational quality. Document the rationale so resource choices are defensible.
What should an auditor examine in electronic records and computerized systems?
Evaluate access control, audit trails, data changes, retention, retrieval, backup, security, and evidence of unauthorized activity or fraud. Confirm that records remain attributable, complete, accurate, and available. A clean screen view does not prove the underlying data are controlled.
What are the four cost-of-quality categories?
Prevention costs avoid defects, appraisal costs evaluate conformity, internal-failure costs arise before delivery, and external-failure costs arise after delivery. Audit trends can show whether investment in prevention and effective controls is reducing failure cost and supporting business objectives across connected processes.
Which basic quality tool fits which audit question?
Use Pareto charts to rank categories, cause-and-effect diagrams or 5 Whys to explore causes, flowcharts to expose steps, control charts to study behavior over time, histograms to view distributions, scatter diagrams to explore association, check sheets to collect data, and PDCA to test and standardize improvement.
How do DMAIC and common lean tools support improvement?
DMAIC defines the problem, measures current performance, analyzes causes, improves the process, and controls the gain. Lean tools remove waste and improve flow: 5S organizes work, kanban controls pull, error-proofing prevents mistakes, standard work stabilizes methods, and value-stream mapping exposes delay and waste.
How should an auditor interpret basic statistics, variation, and capability?
Mean, median, and mode describe center; standard deviation and a frequency distribution describe spread and shape. Look for systemic versus isolated patterns and investigate outliers. Common-cause variation belongs to the current system; special causes are specific signals. For a stable process, Cp reflects potential spread-based capability, while Cpk also reflects centering and cannot exceed Cp.
How do random, stratified, and cluster samples differ?
Random sampling gives population members a defined chance of selection. Stratified sampling draws from important subgroups; cluster sampling selects natural groups and examines units within them. Producer risk is rejecting acceptable quality, while consumer risk is accepting unacceptable quality. Confidence and measurement-system adequacy affect how strongly the sample supports a conclusion.
How do lifecycle and risk tools answer different audit questions?
Change control authorizes and assesses change; configuration management preserves the approved baseline. Verification asks whether specified requirements were met, while validation asks whether intended use is met. FMEA studies failure modes, HACCP controls critical hazards, CTQ translates customer needs into measures, and SWOT frames internal and external strategy factors.
Frequently Asked Questions
Which CQA Body of Knowledge is current?
ASQ began testing the 2026 Certified Quality Auditor Body of Knowledge with the April 2026 testing window. It has five domains with 37, 45, 30, 23, and 15 scored questions respectively, for 150 scored questions total.
How many questions and how much time are on the CQA exam?
The computer-delivered exam has 165 multiple-choice questions: 150 scored and 15 unscored pretest questions. Exam time is 5 hours 18 minutes inside a 5.5-hour appointment. The paper-and-pencil version has 150 multiple-choice questions and allows 5 hours.
What score is required to pass CQA?
ASQ requires a scaled score of 550 out of 750. This is not a statement that candidates need a fixed 73.3% of questions correct. ASQE establishes a raw cut score for the Body of Knowledge and uses scaled scoring and equating to maintain a consistent competence standard across forms.
What is the official CQA pass rate?
ASQ's latest currently published annual table reports a 72% CQA pass rate for 2024, following 73% in 2023 and 70% in 2022. These historical cohort rates do not predict an individual candidate's result.
Who is eligible to apply for CQA?
ASQ requires eight years of full-time, paid experience in one or more CQA BoK areas, including three years in a decision-making position. One education waiver may reduce the eight-year requirement: one year for a technical or trade diploma, two for an associate degree, four for a bachelor's degree, or five for a master's or doctorate.
Is the CQA examination open book?
Yes. ASQ requires all reference materials and notes to be bound and to remain bound during the exam. Ring binders, spiral binders, and other qualifying fasteners are allowed; unbound notes are not. The test administrator inspects references before entry.
What is the CQA retake policy?
ASQ sets no lifetime attempt limit, but a candidate cannot retake within the same testing window. A retake must occur within two years of the previous attempt to use the retake process; otherwise a new application and full certification fees are required.
How does CQA recertification work?
CQA must be recertified every three years. A certificant can document at least 18 recertification units during the three-year period or recertify by examination under ASQ's current rules.
Does the CQA exam include case studies?
Yes. ASQ says approximately 10–15% of the exam is devoted to case studies. Each presents an audit scenario with supporting documents, followed by four-choice questions that require candidates to evaluate realistic evidence and situations.
Explore More ASQ Quality Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
More From This Family
Videos and articles for deeper review.