Audit Types, Planning, and Nonconformance Control

Key Takeaways

  • First-party, second-party, and third-party audits describe different relationships to the audited organization.

  • Audit purpose, scope, criteria, evidence, and reporting guide a defensible audit.

  • Identify and prevent unintended use of unfit equipment using effective status and containment controls.

Last updated: October 2026

A quality system that is never evaluated inevitably suffers from procedural entropy: shortcuts become habit, ambient monitoring lapses, and uncalibrated accessories creep onto active benches. In modern metrology, Quality Auditing provides the structured, objective mechanism to verify that laboratory operations strictly adhere to documented procedures, customer mandates, and accreditation standards. When deviations or measurement failures occur, robust Nonconformance Management and Corrective Action (CAPA) protocols ensure immediate containment, comprehensive customer impact assessment, and the elimination of root causes.


Quality Auditing Principles and the Audit Lifecycle (ISO 19011)

ISO 19011 treats an audit as an organized, documented evaluation of objective evidence against identified criteria, with appropriate independence. Establish scope, criteria, competent auditors, sampling, evidence, findings, reporting, and follow-up. A useful phase grouping is an implementation aid, not a universal required count.

Classification of Audits by Relationship

  • First party: The laboratory audits its own system; maintain objectivity and independence as practicable.
  • Second party: A customer, or someone acting for the customer, audits a supplier against relevant requirements.
  • Third party: An independent external body assesses the organization, such as an accreditation body assessing technical competence. Payment for an assessment does not turn it into a customer supplier audit.

Relationship describes who initiates and performs the audit; system, process, and product describe its focus. One audit can have both classifications.

Classification of Audits by Scope and Focus

  • System Audit: Evaluates the overarching quality management system in its entirety. The auditor examines high-level policies, management reviews, document control, personnel training files, and complaint handling against all clauses of ISO/IEC 17025.
  • Process Audit: Follows a specific operational sequence or workflow from inception to completion. For example, an auditor may follow a torque wrench calibration process from initial receipt, cleaning, environmental soak, pre-loading, calibration runs, data entry, certificate generation, to packaging.
  • Product/calibration audit: Examine an output, such as a certificate and supporting records, against requirements. Witnessing or repeat measurement can be useful when appropriate; auditing does not universally require recalibrating each selected artifact.

The ISO 19011 Audit Lifecycle

Every formal audit progresses through five useful phases:

  1. Audit Initiation and Planning: Define audit objectives, scope, criteria (e.g., ISO/IEC 17025:2017), and schedule. The lead auditor constructs an Audit Plan and ensures independence—auditors must never audit their own direct work (an audit-program independence safeguard; this is not the wording of clause 8.8.2.c).
  2. Opening Meeting: Convene with laboratory leadership and technical staff to review audit scope, confirm communication channels, verify sampling methodologies, and clarify safety protocols.
  3. Gathering and Verifying Objective Evidence: Auditors gather facts using four primary methods:
    • Document & Record Review: Examining calibration procedures, software validation files, check standard control charts, and calibration certificates.
    • Direct Observation: Watching technicians perform live calibrations to verify procedural adherence, environmental monitoring, and lead dress.
    • Personnel Interviews: Questioning technicians on technical principles, decision rules, and out-of-tolerance handling.
    • Physical Inspection: Inspecting environmental loggers, grounding connections, and quarantine lockers.
  4. Audit Finding Categorization: Documenting observations against specific standard clauses.
  5. Closing Meeting and Formal Report: Presenting audit conclusions to laboratory management, clarifying findings, establishing formal response deadlines, and issuing the signed Audit Report.

Categorization of Audit Findings

Findings must be supported by verifiable objective evidence and are categorized based on risk to measurement integrity:

Finding CategoryDefinition & CriteriaLaboratory ExampleRequired Action
Major NonconformityThe complete absence or systemic breakdown of a required QMS element; or any condition directly compromising measurement integrity or traceability.Using an uncalibrated primary standard to certify customer equipment; technicians backdating records; unqualified staff issuing certificates.Immediate containment, stop-work authority, comprehensive root cause analysis, and verification appropriate to the finding before closure.
Minor NonconformityA single, isolated procedural lapse that does not compromise overall calibration integrity or result validity.An uncalibrated thermohygrometer found on a bench where a calibrated master wall sensor confirmed proper room conditions (20.1∘C20.1^\circ\text{C}).Root cause analysis and corrective action implementation within a defined timeframe (the audit-program or agreed response deadline).
Observation / OFIA condition that fully meets current requirements but indicates a potential vulnerability or opportunity to enhance efficiency.Calibration worksheets rely on manual data entry where automated LIMS RS-232 direct capture would eliminate transcription risk.Reviewed during management review; no formal corrective action response legally mandated by the registrar.

Nonconformance Identification and Containment Protocols

Under ISO/IEC 17025:2017 Clause 7.10, a laboratory must have a documented procedure that is implemented when any aspect of its laboratory activities or results of these activities do not conform to its own procedures or the agreed requirements of the customer.

Out-of-Tolerance (OOT) Conditions

In calibration, the most frequent and critical technical nonconformance is an Out-of-Tolerance (OOT) event. An OOT occurs when an item of Inspection, Measurement, and Test Equipment (IM&TE) or a laboratory reference standard exhibits an As-Found measurement error that exceeds its manufacturer specification or contractual tolerance limits:

Condition: ∣Measured Error∣=∣Vindicated−Vnominal∣>Tolerance (MPE)\text{Condition: } |\text{Measured Error}| = |V_{\text{indicated}} - V_{\text{nominal}}| > \text{Tolerance (MPE)}

Immediate Containment Protocols

The moment an OOT condition, instrument damage, or procedural deviation is identified, strict containment protocols must be executed instantly:

  1. Stop-Work Authority: Personnel follow the documented authority and escalation process; technicians should stop affected measurements and report suspected invalid work. When a reference standard is suspected of drift or malfunction, testing must halt immediately without fear of reprisal.
  2. Status Identification: Clearly identify an unfit item and prevent unintended use. The laboratory may use a red out-of-service tag with identifying information, but ISO/IEC 17025 does not mandate one color or exact label text.
  3. Physical Quarantine: Tagging alone is insufficient. The nonconforming item must be prevented from unintended use using effective controls; physical segregation, a locked area, or reliable electronic control can be appropriate to prevent inadvertent retrieval by other technicians.
  4. Electronic Status Control: Where a LIMS is used, update status and prevent selection of unfit equipment through effective controls. The particular software flag and lockout implementation depend on the system.
Test Your Knowledge

An external audit conducted on a commercial calibration laboratory by an authoritative accreditation body such as A2LA or NVLAP to assess compliance with ISO/IEC 17025 is classified under which audit category?

A

First-party audit

B

Second-party audit

C

Internal system audit

D

Third-party audit

Sections you finish are checked off in the contents.