12.1 Quality Auditing Principles & Types
Key Takeaways
- Per ISO 19011, a quality audit is a systematic, independent, and documented process for obtaining objective evidence and evaluating it objectively to determine the extent to which audit criteria are fulfilled.
- Audits are categorized by relationship into first-party (internal), second-party (customer auditing supplier), and third-party (independent registrar or statutory regulatory agency), and separately by method into desk, on-site, and virtual (remote) audits -- method and relationship are independent.
- Audits are categorized by scope into Quality Management System (QMS) audits, Process audits (evaluating parameters, machines, and work instructions), and Product audits (verifying physical hardware against engineering specifications).
- Audit findings are strictly classified into Major Nonconformances (systemic QMS breakdown or risk of shipping nonconforming product), Minor Nonconformances (isolated procedural lapses), and Opportunities for Improvement (OFIs).
- Quality technicians support audits by maintaining calibration and training records, acting as professional auditees who present concise factual evidence, and serving as audit escorts.
12.1 Quality Auditing Principles & Types
Foundational Principles and Definition of a Quality Audit
In modern manufacturing and service environments, quality assurance relies on structured verification rather than passive assumption. Organizations must continuously verify that their processes conform to established procedures and achieve intended outcomes. The primary vehicle for this verification is the quality audit.
Under ISO 19011 (Guidelines for auditing management systems), a quality audit is defined as:
[!IMPORTANT] Quality Audit (ISO 19011): A systematic, independent, and documented process for obtaining audit evidence and evaluating it objectively to determine the extent to which audit criteria are fulfilled.
To fully grasp this definition for the ASQ CQT exam, candidates must break down its three foundational components:
- Audit Criteria: The reference set of policies, procedures, work instructions, blueprints, technical standards (e.g., ISO 9001, AS9100), or contractual requirements against which the auditor compares collected data.
- Audit Evidence: Verifiable records, statements of fact, qualitative observations, or quantitative measurement data collected during the audit. The bedrock rule of quality auditing states: "If it is not supported by verifiable objective evidence, it does not exist as an audit finding."
- Audit Findings: The results of the evaluation of the collected audit evidence against the audit criteria. Findings indicate either conformity, nonconformance, or opportunities for improvement.
The Seven Guiding Principles of Auditing (ISO 19011)
ISO 19011 outlines seven core principles that ensure an audit remains an effective, reliable tool that provides credible management information:
- Integrity: Auditors must perform their work with honesty, diligence, responsibility, and strict adherence to ethical standards.
- Fair Presentation: The obligation to report audit findings, conclusions, and reports truthfully, accurately, and without bias.
- Due Professional Care: The application of reasoned judgment, diligence, and metrological competence during all audit activities.
- Confidentiality: Discretion in the protection and security of sensitive proprietary information acquired during the audit.
- Independence: The basis for the impartiality of the audit and the objectivity of audit conclusions. Auditors must remain free from bias, conflict of interest, and—crucially—must not audit their own work.
- Evidence-Based Approach: The rational method for reaching reliable, reproducible audit conclusions in a systematic audit process. Evidence must be verifiable through physical sampling, record examination, or direct observation.
- Risk-Based Approach: An auditing approach that considers organizational and operational risks and opportunities when planning, conducting, and reporting audits.
Audit Classification by Organizational Relationship
Audits are primarily classified by the contractual or organizational relationship between the auditor and the auditee: first-party, second-party, and third-party audits.
| Audit Category | Designated Term | Auditor Relationship | Primary Purpose & Objectives |
|---|---|---|---|
| First-Party | Internal Audit | Conducted by the organization's own trained personnel (or hired third-party contractors acting internally) on its own processes. | Evaluates internal QMS health, verifies adherence to work instructions, prepares for external assessments, and drives continual improvement. Auditors must be independent of the specific department being audited. |
| Second-Party | Customer-Supplier Audit | Conducted by a customer (or on behalf of a customer) upon a current or prospective supplier/contractor. | Evaluates vendor capability, qualifies new suppliers before purchase order award, assesses supplier process controls, or investigates chronic defective shipments. |
| Third-Party | Certification / Regulatory Audit | Conducted by independent external auditing bodies, accredited registrars, or statutory regulatory agencies. | Grants formal accredited registration (ISO 9001, AS9100, IATF 16949) or enforces statutory/regulatory compliance (FDA 21 CFR 820, FAA 14 CFR Part 21, OSHA, NRC). Results can result in certification, license revocation, or legal penalties. |
Key Nuances Tested on the ASQ CQT Exam
- Auditor Independence in Internal Audits: While an internal auditor is an employee of the company, they cannot audit their own routine work or their own department. For example, a quality technician assigned to the incoming inspection crib cannot audit the incoming inspection calibration or sampling process; an auditor from calibration, assembly, or manufacturing engineering must audit that area.
- Second-Party Legal Standing: Second-party audits are governed by contract law and commercial purchase agreements. The supplier must grant facility access according to the purchase order quality clauses.
- Third-Party Registrar Neutrality: Registrars (such as BSI, TÜV, DNV, or Intertek) have no customer-supplier commercial stake in the product. They evaluate conformity strictly against the standard. Furthermore, registrars are legally barred from providing consulting services to the companies they audit.
Audit Classification by Object and Scope
In addition to relationship-based categorization, quality audits are classified according to their physical scope and investigative depth: Quality Management System (QMS) audits, Process audits, and Product audits.
AUDIT SCOPE PYRAMID:
/\
/ \ [ Product Audit ] --> Checks finished hardware/parts
/----\ against technical prints & specs
/ \ [ Process Audit ] --> Checks machine parameters, SOPs, fixturing,
/--------\ and operator controls on a specific line
/ \ [ System (QMS) Audit]--> Checks broad organizational policies, manuals,
/------------\ management reviews, and cross-functional flow
1. Quality Management System (QMS) Audits
A System Audit evaluates the overall effectiveness, structure, and operational deployment of an organization's documented Quality Management System across all departments. It examines high-level governance processes: management reviews, internal audit systems, corrective and preventive action (CAPA) tracking, document control, resource management, and customer satisfaction metrics.
- Focus: Systemic integration and policy execution.
- Criteria: ISO 9001, AS9100, ISO 13485, Quality Manual.
2. Process Audits
A Process Audit is an in-depth, sequential examination of a specific manufacturing, assembly, special processing (heat treating, anodizing, welding), or inspection process. It verifies that inputs, actions, controls, environmental factors, and outputs function strictly in accordance with documented work instructions and process control plans.
- Focus: Process parameters (temperatures, feeds, speeds, pressures, cycle times), tooling wear, gage calibration at the station, operator training certifications, and material routing travelers.
- Technician's Role: Quality technicians frequently conduct or assist in process audits on the shop floor, checking that setups match active Process Failure Mode and Effects Analysis (PFMEA) controls.
3. Product Audits
A Product Audit is an independent, detailed technical inspection or functional testing of a completed product (or subassembly) after it has passed all standard manufacturing and inspection operations. It serves as an independent final customer verification.
- Focus: Physical dimensions, surface finish ($R_a$), functional performance, packaging integrity, labeling, barcoding, and documentation completeness.
- Sampling: Conducted on packaged, dock-ready inventory or finished lots in the shipping warehouse.
Summary Comparison of Audit Types by Scope
| Attribute | System (QMS) Audit | Process Audit | Product Audit |
|---|---|---|---|
| Primary Target | Organizational policies, manuals, and systemic procedures | Specific sequence of operations or manufacturing step | Finished hardware, components, or packaged units |
| Primary Criteria | ISO/AS standards, Quality Manual, company policies | Work Instructions (SOPs), Control Plans, machine parameters | Blueprints, CAD models, purchase order specifications |
| Typical Auditor | Lead Auditor, Quality Manager, Registrar Auditor | Quality Engineer, Quality Technician, Process Specialist | Quality Inspector, Quality Technician, Test Specialist |
| Investigation Depth | Broad, horizontal scope across multiple departments | Deep, vertical dive into a single machine/workstation | Technical, physical, and metrological inspection of hardware |
Audit Methods: Desk, On-Site, and Virtual Audits
Audits are also classified by how they are conducted, and the CQT Body of Knowledge lists the virtual audit alongside the traditional internal, external, system, process, and product types.
| Method | What it is | What it verifies well | What it cannot verify |
|---|---|---|---|
| Desk audit (document review) | Off-site or preliminary evaluation of the auditee's written documentation: quality manual, procedures, organization charts, previous audit reports | Adequacy — does the documented system, on paper, satisfy the requirements of the governing standard? | Whether anyone actually follows it |
| On-site audit (fieldwork) | Physical audit conducted in the factory, cleanroom, laboratory, or office | Implementation and effectiveness — do personnel execute the process as documented, and does it achieve the intended result? | Nothing inherently; it is the reference method |
| Virtual (remote) audit | Audit of a site conducted through information and communication technology: live video walk-throughs, screen-shared records and ERP/QMS systems, remote interviews, streamed camera feeds | Document and record control, system data, interviews, competence, traceability through electronic records | Housekeeping, part handling and segregation, smell/noise/vibration cues, unsupervised areas, and anything the camera is not pointed at |
A typical third-party registrar audit begins with a Stage 1 desk audit (document review) before deploying auditors for a Stage 2 on-site audit.
Virtual Audits in Practice
Virtual auditing became mainstream when travel restrictions forced it, and it has remained in the toolkit for supplier surveillance, multi-site programmes, and follow-up verification. A technician supporting one needs to know its specific requirements and limits:
- The scope must state what is being audited remotely and what will be deferred to a future on-site visit. An audit cannot claim on-site coverage it did not perform.
- Information security and confidentiality must be agreed in advance: which systems the auditor may see, whether recording is permitted, and how screen-shared documents are handled.
- Evidence still has to be objective and verifiable. A record shown on a shared screen is evidence; a record described verbally is not. Auditors normally ask the auditee to navigate to the record live rather than to send a pre-selected copy.
- Sample selection must remain with the auditor. Remote auditing makes it easy for the auditee to present a curated set of records, which is exactly the failure mode described in Section 12.3.
- Live video walk-throughs need a plan: a defined route, a camera operator briefed in advance, and the auditor directing where the camera points rather than following a tour.
- Connectivity and hardware failures are audit risks, not excuses. The audit plan states what happens if the link fails mid-audit.
[!NOTE] Virtual is a method, not a relationship. A virtual audit can be first-party, second-party, or third-party. Candidates who see "virtual" in an answer choice sometimes treat it as a fourth relationship category alongside first, second, and third party. It is not: the relationship is determined by who audits whom, and the method is determined by how.
The Audit Lifecycle at a Glance
Every audit, whatever its type or method, follows the same four phases. This section covers what each phase is for; the operational mechanics of planning, conducting, and reporting are the subject of Section 12.2, and the tools used inside them are the subject of Section 12.3.
THE AUDIT LIFECYCLE:
[ PHASE 1: PLANNING ] Purpose: agree what will be audited, against what,
Scope -> Criteria -> and make the audit possible to execute.
Plan -> Checklists
|
v
[ PHASE 2: EXECUTION ] Purpose: gather sufficient objective evidence
Interviews -> Observation through interviews, direct observation,
-> Records -> Corroboration and examination of records.
|
v
[ PHASE 3: REPORTING ] Purpose: evaluate the evidence against the criteria,
Classify findings -> classify and communicate the findings, and
Closing meeting -> Report issue the formal record.
|
v
[ PHASE 4: CLOSURE ] Purpose: confirm the auditee eliminated the cause
Corrective action -> and that the action worked, then close.
Verification -> Closure
Two lifecycle rules are tested directly and are worth fixing in memory now:
- Evidence before conclusion. A finding exists only when verifiable objective evidence has been compared against an agreed criterion. Auditors corroborate an interview statement with physical observation and documented records rather than relying on any single source.
- The audit is not finished at the closing meeting. It is finished when corrective actions have been implemented, verified by objective evidence, and formally closed.
The Role of the Quality Technician in Quality Audits
Quality technicians play vital operational roles before, during, and after quality audits:
1. Serving as an Auditee
When interviewed by internal, customer, or registrar auditors, technicians must adhere to strict professional auditee etiquette:
- Answer Only the Question Asked: Provide concise, factual, and direct answers. Do not volunteer speculative information, voice personal complaints about management, or discuss departments outside your responsibility.
- Show, Don't Just Tell: Support verbal statements with physical objective evidence. Walk the auditor through the approved work instruction, pull the controlled drawing revision from the computer portal, or demonstrate how gage zero is checked against a master ring.
- Never Guess or Fabricate: If you do not know the answer, state honestly: "I do not know that offhand, but that procedure is documented in our calibration manual, and I can retrieve it for you." Guessing or providing inaccurate information invites further scrutiny and nonconformances.
2. Serving as an Audit Escort
Technicians frequently escort external auditors through manufacturing areas. Responsibilities include:
- Ensuring auditors wear required Personal Protective Equipment (ANSI Z87.1 safety glasses, steel-toe footwear, hearing protection).
- Guiding auditors safely along designated walking aisles away from moving machinery.
- Introducing auditors to cell operators and retrieving requested travelers, calibration logs, and blueprints promptly.
3. Assisting in Internal Process and Product Audits
Quality technicians often participate as internal audit team members. They inspect travelers for missing sign-offs, verify gage calibration stickers, check that nonconforming parts are segregated in locked red bins, and audit process parameters against approved control plans.
4. Maintaining Audit Readiness
Technicians maintain daily audit readiness by ensuring:
- All measuring instruments display current, legible calibration stickers.
- Expired or damaged gages are immediately removed from service and quarantined.
- Inspection sheets and routing travelers are filled out completely with no blank data fields or uninitialed cross-outs.
- Workstations display only current controlled revisions of drawings and SOPs.
Common Exam Traps for CQT Candidates
[!CAUTION] Trap 1: Who Classifies the Audit? Exam questions often describe a customer auditing a supplier and ask for the classification. Candidates mistakenly choose "third-party" because the auditor is external. Remember: A customer auditing a supplier is always a second-party audit!
Trap 2: Can Auditors Prescribe Solutions? Auditors identify nonconformances against criteria; they do not design, dictate, or prescribe corrective solutions. Doing so compromises their independence and impartiality.
Trap 3: Major vs. Minor Nonconformance Distinction. Distinguish between an isolated human slip (Minor) and an absence of a system or direct shipment of nonconforming product (Major). A single missing signature is Minor; completely missing training or calibration systems is Major.
Trap 4: Product vs. Process Auditing. Process audits verify parameters, machines, and instructions during production. Product audits inspect finished hardware after all production operations are completed.
An aerospace component manufacturer is audited by an independent accredited registrar to determine whether its facility meets the requirements for AS9100 certification. Simultaneously, a commercial airline customer conducts an audit of the facility's heat-treating line before approving a new purchase contract. How are these two audits classified by organizational relationship?
A quality audit team visits a precision CNC milling department. The auditors select ten finished aluminum brackets from the packaging station and independently verify their hole diameters, surface finish, and anodizing thickness against blueprint engineering specifications. What specific type of audit by object/scope has been performed?
During a third-party ISO 9001 surveillance audit, a quality technician is asked by the auditor how they know which revision of an inspection instruction is current and where to find it. Which response represents the correct, professional auditee protocol?