4.3 Pre-Audit Documentation & Gap Assessments

Key Takeaways

  • Pre-audit document review uses criteria references, prior audit results, performance data, and process information to refine scope, risk focus, checklists, and logistics before arrival.
  • Gap assessments compare current practices or documented systems against criteria to identify likely weak areas—guiding sampling depth, not pre-writing nonconformities without evidence.
  • Prior audit results (internal, customer, certification, regulatory) are high-value inputs for follow-up of open CAPAs, recurring themes, and verification planning.
  • Document requests should be timely, version-specific, and proportional to purpose; remote review of controlled documents is common in hybrid formats.
  • Analyze-level skill for II.A.3 means interpreting document sets and history to adjust the plan—not treating paper review as optional decoration.
Last updated: August 2026

4.3 Pre-Audit Documentation & Gap Assessments (CQA BoK II.A.3 — Analyze)

Quick Answer: Before fieldwork, auditors request and review relevant documentation—QMS manuals, procedures, quality agreements, specs, metrics, and prior audit results—and often perform a gap assessment against criteria. The goal is to refine risk focus, checklists, logistics, and questions. Analyze-level skill means using those inputs to adjust the plan, not merely filing PDFs. Pre-review does not replace on-site evidence and must not invent findings from assumptions alone.

Walking in cold wastes auditor-days and signals amateur planning. II.A.3 expects disciplined pre-audit analysis.


What to Request (and Why)

Criteria-linked document set

Build the request from the criteria stack and process map:

Document categoryPlanning value
Quality manual / process landscapeSystem structure, interactions, exclusions
Procedures & work instructions for in-scope processesCurrent requirements (criteria detail)
Quality policy & objectives / KPIsEffectiveness focus areas
Contracts & quality agreementsSecond-party shalls, access rights, notification rules
Product/process specifications & control plansProduct/process audit depth
Org charts & responsibility matricesInterview targets, independence checks
Training matrices for critical rolesCompetence risk signals
Calibration / validation master listsMeasurement system risk
NCR, complaint, CAPA logs (period defined by scope)Failure modes and chronic issues
Management review outputs (recent)Leadership attention themes
Prior audit reports & CAPA statusFollow-up and recurring gaps
Change-control logs (recent)New risk after process/product change
IT/system validation summaries (if e-records critical)Data-integrity planning
Site maps, shift patterns, PPE/safety rulesLogistics (links to 4.4)

Proportionality: A narrow CAPA verification needs the prior finding, CAPA plan, related procedures, and effectiveness evidence—not the entire QMS binder. A full system audit needs broader coverage but still prioritizes high-risk processes.

Timing and version control

  • Request early enough for translation, redaction, and access provisioning.
  • Specify effective revisions and date ranges for records.
  • Prefer controlled electronic access over emailed uncontrolled copies when possible.
  • Log what was received, what was missing, and impact on the plan.

Scenario — incomplete package.
For a supplier qualification, the auditee sends a glossy brochure and last year’s certificate but withholds the quality agreement annex and CAPA log. Analysis: high risk—criteria and history incomplete. Actions: escalate using contractual right-of-access, delay on-site visit if critical documents absent, or document a scope limitation if the client proceeds. Do not invent a clean bill of health from marketing materials.


Prior Audit Results: Gold for Planning

Prior results include internal audits, second-party customer audits, third-party certification/surveillance, regulatory inspections, and previous CAPA verifications.

How to analyze them

  1. Open actions: Which CAPAs remain open or overdue? Schedule verification samples.
  2. Recurrence: Same clause/process failing repeatedly → deeper sampling and system-level questions (root cause of weak CAPA).
  3. Closures without effectiveness: “Implemented” but metrics unchanged → effectiveness focus.
  4. Strengths: Avoid wasting time re-proving mature areas unless risk changed.
  5. Conflicts between parties: Customer major vs. internal “all green” → independence and culture risk.
  6. Scope history: Areas never audited in the cycle → coverage debt.
Prior signalPlanning response
Major NC in change control last yearExtra time, sample recent changes, interview owners
Clean history but new ERP go-liveShift focus to data migration, access control, release logic
Customer audit found labeling errorsProduct audit samples on labeling + training
Certification body reduced samplingDo not copy reduction if your purpose is deeper internal risk review

Exam trap: Treating prior clean results as proof of current conformity without sampling. Prior results guide risk; they are not current evidence for this audit’s conclusion.


Gap Assessments

A gap assessment (gap analysis) compares the auditee’s documented system and/or known practices against criteria to identify missing, weak, or ambiguous requirements coverage—before or at the start of detailed auditing.

Legitimate uses in audit planning

  • Identify clauses/processes with no documented controls → plan interviews and floor verification.
  • Spot obvious document conflicts (two procedures, different calibration intervals) → plan which is effective and whether practice matches either.
  • Flag new standard revisions not yet addressed → plan transition sampling.
  • Support readiness reviews before certification (still need independent audit evidence later).

What gap assessment is not

MisuseWhy wrong
Writing nonconformities from the gap list without objective evidenceViolates evidence-based auditing
Replacing the audit with a document-only checklist tickMisses implementation and effectiveness
Using another company’s gap template as secret criteriaWrong criteria source
Ignoring positive prior performance entirelyWastes resources; unbalanced

Scenario — constructive gap use.
Pre-review of a medical-device QMS against ISO 13485 shows no procedure addressing unique device identification (UDI) though product is marketed in a UDI-regulated region. Planning response: add UDI process to scope emphasis, request related records, assign SME time—not write an NC yet. Fieldwork then confirms whether UDI is controlled under another document name or truly missing.


Analyzing Documents Against Criteria (Worked Method)

  1. Extract shalls from criteria (standard clauses, quality agreement, internal SOPs).
  2. Map each shall to a document or process owner.
  3. Note voids (no document), conflicts (two documents disagree), vagueness (unmeasurable requirements), and obsolescence (references to retired systems).
  4. Cross-check performance data (complaints, scrap, on-time quality) for processes that look fine on paper.
  5. Translate into checklist questions and sample sizes.
  6. Update risk ranking and daily itinerary.

Paper vs. practice mindset

Pre-audit review is biased toward what is written. Analyze deliberately for implementation risk:

  • Procedures revised yesterday after the audit was announced (possible window dressing).
  • Perfect metrics with no raw data available remotely (verify on-site).
  • Training records 100% complete for a process with rising errors (competence vs. attendance).

Remote Document Review & Hybrid Planning

Hybrid audits often complete much of II.A.3 offline:

  • Secure portals for controlled documents.
  • Screen-share walkthroughs of e-QMS and ERP.
  • Advance questionnaires (use carefully—answers are auditee claims, still need verification).

Controls:

  • Authenticity (are we seeing the live controlled copy?).
  • Confidentiality (NDAs, access expiry).
  • Completeness (sampling across the records period, not only best examples).

If remote review reveals the quality agreement is expired or the process was outsourced, re-evaluate purpose/scope before travel.


Outputs of Pre-Audit Analysis

A complete pre-audit package feeds:

  • Updated audit plan (scope tweaks, extra SME day, remote vs. on-site split).
  • Risk-ranked process list.
  • Tailored checklists citing criteria.
  • Interview schedule targets.
  • Follow-up list of prior CAPAs.
  • Logistics notes (classified areas, cleanroom docs needed before entry).
  • Open questions for the opening meeting.

Communication with the auditee

Share enough of the plan and document list for preparation, without turning the audit into a scripted play. Surprise is not the goal; unbiased evidence is. Hiding the criteria until arrival is usually counterproductive and unprofessional.


Common Exam Scenarios

Stem patternStrong analysis
Team skips document review to “save time”Planning defect; higher risk of missed criteria and poor sampling
Gap list treated as final NCsImproper—needs objective evidence and evaluation
Prior majors ignoredMissed follow-up obligation and risk focus
Only marketing certificates reviewedInsufficient for technical qualification purpose
Documents show conflict; plan unchangedFailure to adjust checklist and interviews
Client forbids access to prior regulatory lettersLimitation—assess impact on objectives; escalate

Key Exam Anchors

  • Pre-audit work: criteria references, document review, prior results, gap assessment, plan adjustment.
  • Gap assessment guides sampling; it does not replace evidence-based findings.
  • Prior audits drive follow-up and recurrence analysis.
  • Document requests are purpose-proportional and version-aware.
  • Analyze = interpret the package and change the plan accordingly.
Test Your Knowledge

What is the most appropriate use of a pre-audit gap assessment?

A
B
C
D
Test Your Knowledge

Prior certification audits closed three majors in change control; CAPAs are marked complete. How should the planning team analyze this?

A
B
C
D
Test Your Knowledge

Which pre-audit document set is most critical for a second-party supplier qualification audit?

A
B
C
D
Test Your Knowledge

Remote pre-review shows the auditee’s quality agreement expired and a critical process was outsourced last month. What should the team do?

A
B
C
D