6.2 Quality Auditing & Compliance Management

Key Takeaways

  • ISO 19011:2018 establishes international guidelines for auditing management systems based on key principles including integrity, independence, and evidence-based sampling.
  • First-party audits are internal evaluations, second-party audits assess suppliers/vendors, and third-party audits are conducted by independent registrars for formal certification or regulatory compliance.
  • The complete audit lifecycle follows four sequential phases: Planning/Initiation, Execution (On-Site/Remote), Reporting, and Closure/Follow-Up.
  • Audit findings are classified by severity into Major Nonconformities, Minor Nonconformities, and Opportunities for Improvement (OFIs).
  • Verification of corrective action effectiveness—not just approving a written corrective action plan—is required before an audit can be formally closed.
Last updated: July 2026

Quality Auditing & Compliance Management

Quality auditing is an essential, independent management tool used to evaluate process compliance, assess system effectiveness, and identify opportunities for organizational improvement. In a robust Quality Management System (QMS), audits provide executive leadership with objective evidence regarding whether operational activities comply with planned arrangements, international standards (such as ISO 9001, AS9100, or IATF 16949), and statutory regulatory requirements.

For the ASQ CMQ/OE exam, candidates must understand audit classifications, master the guidelines set forth in ISO 19011:2018, and navigate every phase of the audit lifecycle from initiation to corrective action verification.


Fundamentals of Quality Auditing

An audit is defined by ISO 9000 as a "systematic, independent, and documented process for obtaining audit evidence and evaluating it objectively to determine the extent to which audit criteria are fulfilled."

ISO 19011:2018 Principles of Auditing

Auditing relies on seven fundamental principles that ensure the audit serves as an effective, reliable tool for executive decision making:

  1. Integrity: The foundation of professionalism. Auditors must perform work with honesty, diligence, responsibility, and strict compliance with legal requirements.
  2. Fair Presentation: The obligation to report truthfully and accurately. Audit findings, conclusions, and reports must reflect audit activities objectively without distortion.
  3. Due Professional Care: Applying diligence, sound judgment, and competence in accordance with the importance of the task and the confidence placed in the auditor by audit clients.
  4. Confidentiality: Maintaining strict security and discretion over propriety information acquired during audit duties.
  5. Independence: The basis for audit impartiality and objectivity. Auditors must be independent of the activity being audited wherever practicable and must remain free from bias and conflict of interest.
  6. Evidence-Based Approach: The rational method for reaching reliable audit conclusions. Audit evidence must be verifiable, based on samples of operational data, records, or direct physical observations.
  7. Risk-Based Approach: An auditing principle that considers risks and opportunities when planning, conducting, and reporting audits to ensure resources are focused on matters of significance.

Exam Tip: ASQ exam questions regularly test Independence. An internal auditor must never audit their own direct work or department. Independence guarantees that objective evidence, rather than personal bias, drives audit conclusions.


Classifications and Types of Audits

Audits are classified either by the relationship between parties (1st, 2nd, or 3rd party) or by the scope/object of the audit (System, Process, or Product).

                                AUDIT TYPES BY RELATIONSHIP
┌──────────────────────────────────┐┌──────────────────────────────────┐┌──────────────────────────────────┐
│         FIRST-PARTY AUDIT        ││        SECOND-PARTY AUDIT        ││         THIRD-PARTY AUDIT        │
│        (Internal Audit)          ││        (Supplier Audit)          ││       (Certification Audit)      │
│  - Conducted by firm on itself   ││  - Conducted by customer on vendor││  - Conducted by independent body │
│  - Purpose: Internal improvement ││  - Purpose: Vendor qualification ││  - Purpose: ISO/Regulatory cert  │
└──────────────────────────────────┘└──────────────────────────────────┘└──────────────────────────────────┘

Audits Classified by Party Relationship

Audit TypeAuditing PartyPurpose & ScopeKey Benefit
First-Party (Internal)Internal employees or hired consultants auditing their own companyEvaluate QMS effectiveness, assess standard compliance, prepare for management review.Identifies internal process gaps before external detection; drives self-correction.
Second-Party (Supplier)Organization auditing its existing or prospective suppliers / vendorsEvaluate vendor capability, verify contractual compliance, investigate supplier defects.Protects supply chain integrity and enforces technical specification compliance.
Third-Party (Certification / Regulatory)Independent, accredited registrar (BSI, TÜV, DNV) or regulatory body (FDA, FAA, EPA)Formal certification audit against standard criteria (e.g., ISO 9001) or regulatory enforcement inspection.Grants formal accredited registration certificate or statutory license to operate.

Audits Classified by Scope and Objective

  • System Audit: Evaluates the entirety of a management system against standard requirements (e.g., auditing the complete ISO 9001 quality management system).
  • Process Audit: In-depth verification of a specific transformation process, examining inputs, procedure adherence, environmental controls, equipment calibration, and outputs.
  • Product / Service Audit: Evaluation of a completed product, service deliverable, or sub-assembly against physical drawings, customer specifications, or functional standards.

The Audit Lifecycle: Four Sequential Phases

A professional audit follows a structured, four-phase process lifecycle:

Phase 1: Planning ──► Phase 2: Execution ──► Phase 3: Reporting ──► Phase 4: Closure

Phase 1: Planning and Preparation

  1. Define Scope and Criteria: Establish clear geographic, organizational, and process boundaries alongside reference standards (e.g., ISO 9001:2015 Clause 8).
  2. Assign Audit Team: Select qualified auditors ensuring technical competence and zero conflict of interest.
  3. Document Review: Examine relevant quality manuals, SOPs, past audit findings, and process flowcharts.
  4. Formulate Audit Plan & Checklists: Develop a detailed time schedule and prepare working checklists containing open-ended evaluation questions.

Phase 2: Audit Execution (On-Site or Remote)

  1. Opening Meeting: Introduce the audit team to auditee management, confirm the audit plan, clarify communication channels, and confirm resource availability.
  2. Gathering Audit Evidence: Collect evidence using three primary techniques:
    • Interviewing personnel across organizational levels using open-ended questions (Who, What, When, Where, Why, How).
    • Observing physical work activities, environmental conditions, and operator habits.
    • Examining documentation, calibration logs, inspection records, and electronic databases.
  3. Synthesizing Findings: Compare audit evidence against audit criteria to identify nonconformities.
  4. Closing Meeting: Present audit findings and preliminary conclusions to auditee management before drafting the formal report.

Phase 3: Audit Reporting

  1. Prepare a clear, concise, and objective written Audit Report.
  2. Categorize audit findings clearly:
    • Major Nonconformity: A total breakdown of a system requirement, an absence of a mandatory standard clause, or a condition that directly threatens product quality/safety.
    • Minor Nonconformity: An isolated lapse or single procedural slip that does not compromise overall process integrity or product compliance.
    • Opportunity for Improvement (OFI): A statement of potential improvement that does not represent a standard violation.

Phase 4: Audit Closure and Follow-Up

  1. Corrective Action Request (CAR): The auditee conducts a formal root cause analysis (e.g., 5 Whys, Fishbone) and submits a proposed Corrective Action Plan.
  2. Verification of Effectiveness: The auditor must evaluate and verify that the implemented corrective actions have permanently eliminated the root cause and prevented recurrence.
  3. Formal Closure: Once effectiveness is verified with objective evidence, the audit is formally closed.

Auditor Code of Conduct and Communication Techniques

Successful auditors balance technical expertise with refined interpersonal skills:

  • Effective Questioning: Use open-ended questions ("Show me how you verify calibration") rather than closed leading questions ("You always calibrate this tool, right?").
  • Professional Skepticism: Trust, but verify. Statements made during interviews must be backed by verifiable objective evidence.
  • Conflict Resolution: Remain calm, factual, and non-confrontational if an auditee becomes defensive. Refocus conversations on objective reference criteria.
Loading diagram...
Audit Finding Classification and Escalation Path
Test Your Knowledge

A customer sends a team of supplier quality engineers to conduct a comprehensive facility audit of a contract manufacturing partner to verify compliance with contractual quality standards. How is this audit classified by relationship?

A
B
C
D
Test Your Knowledge

According to ISO 19011:2018 guidelines, which fundamental principle of auditing establishes the necessity for audit conclusions to be verifiable and based on sample data?

A
B
C
D
Test Your Knowledge

An auditor completes an internal QMS audit and identifies a major nonconformity in the calibration system. The auditee immediately submits a revised calibration SOP. What step must occur before the audit can be formally closed?

A
B
C
D