4.3 Pre-Audit Documentation & Gap Assessments
Key Takeaways
- Pre-audit document review uses criteria references, prior audit results, performance data, and process information to refine scope, risk focus, checklists, and logistics before arrival.
- Gap assessments compare current practices or documented systems against criteria to identify likely weak areas—guiding sampling depth, not pre-writing nonconformities without evidence.
- Prior audit results (internal, customer, certification, regulatory) are high-value inputs for follow-up of open CAPAs, recurring themes, and verification planning.
- Document requests should be timely, version-specific, and proportional to purpose; remote review of controlled documents is common in hybrid formats.
- Analyze-level skill for II.A.3 means interpreting document sets and history to adjust the plan—not treating paper review as optional decoration.
4.3 Pre-Audit Documentation & Gap Assessments (CQA BoK II.A.3 — Analyze)
Quick Answer: Before fieldwork, auditors request and review relevant documentation—QMS manuals, procedures, quality agreements, specs, metrics, and prior audit results—and often perform a gap assessment against criteria. The goal is to refine risk focus, checklists, logistics, and questions. Analyze-level skill means using those inputs to adjust the plan, not merely filing PDFs. Pre-review does not replace on-site evidence and must not invent findings from assumptions alone.
Walking in cold wastes auditor-days and signals amateur planning. II.A.3 expects disciplined pre-audit analysis.
What to Request (and Why)
Criteria-linked document set
Build the request from the criteria stack and process map:
| Document category | Planning value |
|---|---|
| Quality manual / process landscape | System structure, interactions, exclusions |
| Procedures & work instructions for in-scope processes | Current requirements (criteria detail) |
| Quality policy & objectives / KPIs | Effectiveness focus areas |
| Contracts & quality agreements | Second-party shalls, access rights, notification rules |
| Product/process specifications & control plans | Product/process audit depth |
| Org charts & responsibility matrices | Interview targets, independence checks |
| Training matrices for critical roles | Competence risk signals |
| Calibration / validation master lists | Measurement system risk |
| NCR, complaint, CAPA logs (period defined by scope) | Failure modes and chronic issues |
| Management review outputs (recent) | Leadership attention themes |
| Prior audit reports & CAPA status | Follow-up and recurring gaps |
| Change-control logs (recent) | New risk after process/product change |
| IT/system validation summaries (if e-records critical) | Data-integrity planning |
| Site maps, shift patterns, PPE/safety rules | Logistics (links to 4.4) |
Proportionality: A narrow CAPA verification needs the prior finding, CAPA plan, related procedures, and effectiveness evidence—not the entire QMS binder. A full system audit needs broader coverage but still prioritizes high-risk processes.
Timing and version control
- Request early enough for translation, redaction, and access provisioning.
- Specify effective revisions and date ranges for records.
- Prefer controlled electronic access over emailed uncontrolled copies when possible.
- Log what was received, what was missing, and impact on the plan.
Scenario — incomplete package.
For a supplier qualification, the auditee sends a glossy brochure and last year’s certificate but withholds the quality agreement annex and CAPA log. Analysis: high risk—criteria and history incomplete. Actions: escalate using contractual right-of-access, delay on-site visit if critical documents absent, or document a scope limitation if the client proceeds. Do not invent a clean bill of health from marketing materials.
Prior Audit Results: Gold for Planning
Prior results include internal audits, second-party customer audits, third-party certification/surveillance, regulatory inspections, and previous CAPA verifications.
How to analyze them
- Open actions: Which CAPAs remain open or overdue? Schedule verification samples.
- Recurrence: Same clause/process failing repeatedly → deeper sampling and system-level questions (root cause of weak CAPA).
- Closures without effectiveness: “Implemented” but metrics unchanged → effectiveness focus.
- Strengths: Avoid wasting time re-proving mature areas unless risk changed.
- Conflicts between parties: Customer major vs. internal “all green” → independence and culture risk.
- Scope history: Areas never audited in the cycle → coverage debt.
| Prior signal | Planning response |
|---|---|
| Major NC in change control last year | Extra time, sample recent changes, interview owners |
| Clean history but new ERP go-live | Shift focus to data migration, access control, release logic |
| Customer audit found labeling errors | Product audit samples on labeling + training |
| Certification body reduced sampling | Do not copy reduction if your purpose is deeper internal risk review |
Exam trap: Treating prior clean results as proof of current conformity without sampling. Prior results guide risk; they are not current evidence for this audit’s conclusion.
Gap Assessments
A gap assessment (gap analysis) compares the auditee’s documented system and/or known practices against criteria to identify missing, weak, or ambiguous requirements coverage—before or at the start of detailed auditing.
Legitimate uses in audit planning
- Identify clauses/processes with no documented controls → plan interviews and floor verification.
- Spot obvious document conflicts (two procedures, different calibration intervals) → plan which is effective and whether practice matches either.
- Flag new standard revisions not yet addressed → plan transition sampling.
- Support readiness reviews before certification (still need independent audit evidence later).
What gap assessment is not
| Misuse | Why wrong |
|---|---|
| Writing nonconformities from the gap list without objective evidence | Violates evidence-based auditing |
| Replacing the audit with a document-only checklist tick | Misses implementation and effectiveness |
| Using another company’s gap template as secret criteria | Wrong criteria source |
| Ignoring positive prior performance entirely | Wastes resources; unbalanced |
Scenario — constructive gap use.
Pre-review of a medical-device QMS against ISO 13485 shows no procedure addressing unique device identification (UDI) though product is marketed in a UDI-regulated region. Planning response: add UDI process to scope emphasis, request related records, assign SME time—not write an NC yet. Fieldwork then confirms whether UDI is controlled under another document name or truly missing.
Analyzing Documents Against Criteria (Worked Method)
- Extract shalls from criteria (standard clauses, quality agreement, internal SOPs).
- Map each shall to a document or process owner.
- Note voids (no document), conflicts (two documents disagree), vagueness (unmeasurable requirements), and obsolescence (references to retired systems).
- Cross-check performance data (complaints, scrap, on-time quality) for processes that look fine on paper.
- Translate into checklist questions and sample sizes.
- Update risk ranking and daily itinerary.
Paper vs. practice mindset
Pre-audit review is biased toward what is written. Analyze deliberately for implementation risk:
- Procedures revised yesterday after the audit was announced (possible window dressing).
- Perfect metrics with no raw data available remotely (verify on-site).
- Training records 100% complete for a process with rising errors (competence vs. attendance).
Remote Document Review & Hybrid Planning
Hybrid audits often complete much of II.A.3 offline:
- Secure portals for controlled documents.
- Screen-share walkthroughs of e-QMS and ERP.
- Advance questionnaires (use carefully—answers are auditee claims, still need verification).
Controls:
- Authenticity (are we seeing the live controlled copy?).
- Confidentiality (NDAs, access expiry).
- Completeness (sampling across the records period, not only best examples).
If remote review reveals the quality agreement is expired or the process was outsourced, re-evaluate purpose/scope before travel.
Outputs of Pre-Audit Analysis
A complete pre-audit package feeds:
- Updated audit plan (scope tweaks, extra SME day, remote vs. on-site split).
- Risk-ranked process list.
- Tailored checklists citing criteria.
- Interview schedule targets.
- Follow-up list of prior CAPAs.
- Logistics notes (classified areas, cleanroom docs needed before entry).
- Open questions for the opening meeting.
Communication with the auditee
Share enough of the plan and document list for preparation, without turning the audit into a scripted play. Surprise is not the goal; unbiased evidence is. Hiding the criteria until arrival is usually counterproductive and unprofessional.
Common Exam Scenarios
| Stem pattern | Strong analysis |
|---|---|
| Team skips document review to “save time” | Planning defect; higher risk of missed criteria and poor sampling |
| Gap list treated as final NCs | Improper—needs objective evidence and evaluation |
| Prior majors ignored | Missed follow-up obligation and risk focus |
| Only marketing certificates reviewed | Insufficient for technical qualification purpose |
| Documents show conflict; plan unchanged | Failure to adjust checklist and interviews |
| Client forbids access to prior regulatory letters | Limitation—assess impact on objectives; escalate |
Key Exam Anchors
- Pre-audit work: criteria references, document review, prior results, gap assessment, plan adjustment.
- Gap assessment guides sampling; it does not replace evidence-based findings.
- Prior audits drive follow-up and recurrence analysis.
- Document requests are purpose-proportional and version-aware.
- Analyze = interpret the package and change the plan accordingly.
What is the most appropriate use of a pre-audit gap assessment?
Prior certification audits closed three majors in change control; CAPAs are marked complete. How should the planning team analyze this?
Which pre-audit document set is most critical for a second-party supplier qualification audit?
Remote pre-review shows the auditee’s quality agreement expired and a critical process was outsourced last month. What should the team do?