8.2 Effective Reports: Summary, Findings & OFIs

Key Takeaways

  • Effective reports (BoK II.C.2, Create) include background context, an executive summary, and prioritized observations separated into findings versus opportunities for improvement (OFIs).
  • The executive summary is decision-oriented: purpose, overall conclusion, high-severity issues, and what management must act on—without burying majors in appendix detail.
  • Findings (nonconformities) require response and CAPA pathways; OFIs recommend improvement without implying automatic nonconformity unless the program reclassifies them.
  • State a clear timeline for auditee responses and define what a complete response includes (containment, root cause, corrective action, owners, dates).
  • Exam trap: mixing OFIs into the nonconformity list, or writing a summary that restates every detail instead of prioritizing risk.
Last updated: August 2026

8.2 Effective Reports: Summary, Findings & OFIs (CQA BoK II.C.2 — Create)

/practice/cqaPractice questions with detailed explanations

Section 8.1 built the content of findings. Section 8.2 is about packaging that content into a report that works in the real world: leaders skim, CAPA owners execute, and verifiers later confirm closure. BoK II.C.2 (Create) tests whether you can design that package—not merely list report headings.


Why report structure is a Create skill

A technically correct finding buried on page 14 after twelve compliments will not drive action. An OFI worded like a nonconformity will trigger false CAPA. A report with no response due date stalls the audit process. Creating an effective report means controlling order, labels, priority, and next steps.

ReaderWhat they need firstFailure mode if missing
Senior management / clientOverall conclusion + high-risk issuesMisses systemic risk; under-resources CAPA
Auditee process ownersExact findings, evidence, IDs, due datesVague CAPA or dispute over "what we owe"
Audit program / leadTraceability, consistency with exit meetingCredibility challenge; incomplete file
Follow-up auditorBaseline statements and IDsCannot verify effectiveness

Core sections of an effective report

Programs vary in templates (ISO 19011-aligned internal forms, CB report formats, supplier scorecard packages). The functional blocks below appear across competent designs.

1. Identification and background

Background orients the reader without repeating the entire audit plan:

  • Audit title, unique audit ID, dates, sites/locations (including remote platforms if hybrid).
  • Audit type and purpose (internal system, supplier process, certification surveillance, for-cause, etc.).
  • Scope and criteria (standards, procedures, contracts, regulations actually used).
  • Audit team and lead; auditee contacts.
  • Reference to plan, opening/closing meetings, and any scope limitations or denials of access.
  • Confidentiality and distribution control statements as required by procedure.

Scenario — missing background.
A report lists five findings but never states criteria or scope. Six months later the auditee claims the items were "best practice wishes." Without documented criteria in the report (or clear reference to the controlled plan attached), disputes escalate. Include criteria explicitly.

2. Executive summary

The executive summary is not a polite abstract. It is a management decision brief:

Summary elementIntent
Purpose and scope in one to three sentencesFrame the decision
Overall conclusion (e.g., system effective with exceptions; major nonconformity; recommendation language if in scope)Answer "so what?"
Count and severity profile of findingsShow scale
Highest-risk findings in plain languageDirect attention
Notable positives / strengths (brief, evidence-based)Balance without sugarcoating
Required response timeline and escalation pathTrigger action

Prioritize. If you have one major on sterilization validation records and six minor document typos, the summary leads with sterilization. Do not alphabeticalize risk away.

Scenario — weak vs strong summary.
Weak: "The audit was conducted per plan. Several issues were noted. See attachments."
Strong: "Internal QMS audit of sterile packaging (criteria: ISO 13485 clauses in scope + SOP PKG-10). Overall: QMS implemented with one major nonconformity (incomplete sterilization load release records for 3 of 10 lots sampled — NC-2026-0612-01) and four minors. Response package due 15 business days from report issue. Strength: calibrated equipment control showed full traceability in the sample."

3. Detailed findings (nonconformities)

Present findings in priority order (severity/risk), not discovery order. Each finding block typically includes:

  • Unique ID and severity classification.
  • Requirement / criteria reference.
  • Nonconformity statement.
  • Objective evidence (what, where, when, sample size/extent).
  • Optional risk note or process linkage.
  • Requested response elements (if not covered globally).

Use consistent formatting so CAPA authors can copy IDs into their system without reinterpreting paragraphs.

4. Opportunities for improvement (OFIs) and other observations

OFIs (and similar labels: opportunities, recommendations, positive practices) must be visually and procedurally separated from nonconformities.

Item typeMeansResponse expectation
Finding / nonconformityRequirement not met; objective evidenceMandatory response / CAPA per program
OFIConformity exists or requirement not violated, but improvement would reduce risk or wasteOptional unless management or program elevates
Positive observationStrength worth sustaining/sharingNo corrective action; may feed best-practice transfer
Concern / observation (program-specific)Possible risk without enough evidence for NCFollow-up or more audit time—not automatic NC

Wording discipline. OFI language uses "consider," "opportunity," "could strengthen"—not "failed to" or "nonconformity." If evidence actually shows a requirement failure, write a finding; do not hide NCs as OFIs to keep scorecards green.

Scenario — mislabeled OFI.
"OFI: The recall procedure does not define responsibilities for regulatory notification within required time limits, contrary to SOP REC-01 §6." That is not an OFI—it alleges a requirement gap. Correct action: raise as nonconformity if SOP REC-01 is in criteria and evidence shows the gap.

5. Conclusions and (when in scope) recommendations

Conclusions answer the audit objectives. Examples: suitability/effectiveness of the QMS for the scope; supplier approval recommendation; readiness for certification stage; verification that prior CAPA remains effective. Keep conclusions traceable to findings—do not invent a glowing conclusion above a stack of majors.

6. Response timeline and instructions

II.C.2 explicitly expects attention to timelines for responses. Create clarity:

Timeline elementExample practice
Report issue dateControlled distribution date starts the clock
Response due datee.g., 10–30 calendar/business days per procedure or contract
Severity-based accelerationMajors due sooner than minors
Required response contentContainment (if needed), correction, root cause, corrective action, owners, target dates, effectiveness plan
FormatCAPA form IDs mapped to report finding IDs
EscalationLate or rejected responses → audit boss / management / commercial hold

Scenario — timeline creation.
Supplier audit finds one major on certificate of analysis authenticity controls and two minors on labeling. Contract quality agreement: major responses in 10 business days, minors in 30. Report must state those clocks and that incomplete root-cause statements will be rejected—not merely "please respond soon."


Prioritization techniques that exam items reward

  1. Risk-first ordering inside the summary and the findings section.
  2. Severity labels consistent with the program scheme used at exit.
  3. Clustering related minors under a system theme in the summary while keeping separate IDs in detail.
  4. Explicit "no nonconformities in areas X/Y" only when sampled and in scope—avoid false confidence statements about unvisited areas.
  5. Alignment with exit/closing meeting: written priorities should match what was communicated unless new evidence forced a controlled update.

Common report defects (and how Create-level writers avoid them)

DefectWhy it failsFix
Summary is a table of contentsNo decision valueLead with conclusion + top risks
Findings and OFIs intermixedConfuses mandatory CAPASeparate sections and labels
No criteria in findingsNot auditableCite requirement IDs
No response due dateProcess stallsState timeline and content rules
Surprise majors after soft exitDestroys trustAlign exit and report; control late changes
Personal blame languageLegal/HR risk; poor CAPAProcess/system wording
Endless detail, no priorityManagement disengagesRisk-ranked presentation

Worked mini-structure (template thinking)

Use this mental skeleton when a stem asks "what should the report include?":

  1. Header / audit identification
  2. Background (purpose, scope, criteria, team, dates, limitations)
  3. Executive summary (conclusion, severity profile, top issues, response clock)
  4. Findings (prioritized NCs with IDs)
  5. OFIs / positives (separated)
  6. Conclusions / recommendations (if authorized)
  7. Attachments (optional detailed evidence lists, attendance, distribution list)
  8. Response instructions (what, when, to whom)

Scenario — full package judgment.
A junior auditor submits a report that is only a bullet list of notes with no summary, no IDs, OFIs mixed with NCs, and "respond when you can." As lead, you reject it for rework under II.C.2 expectations: create background, summary, prioritized findings vs OFIs, unique IDs, and a defined response timeline before approval routing (section 8.3).


Exam focus

Expect Create-level items that ask you to:

  • Choose the best executive summary among options.
  • Separate findings from OFIs correctly.
  • Select appropriate response timeline language.
  • Identify missing report elements (background, criteria, prioritization).
  • Recognize when a "recommendation" is actually a hidden nonconformity.

If the report cannot drive a correct CAPA without a phone call to the auditor, it is not yet effective.

Test Your Knowledge

Which executive summary best meets the intent of an effective audit report?

A
B
C
D
Test Your Knowledge

A report states: "OFI: Finished goods were released without completed final inspection records required by Procedure FG-02 §4.4." How should this item be treated?

A
B
C
D
Test Your Knowledge

What should an effective report specify about auditee responses?

A
B
C
D
Test Your Knowledge

Why separate OFIs from findings in the report structure?

A
B
C
D