8.3 Approvals, Distribution & Audit File Retention

Key Takeaways

  • Final report steps (BoK II.C.3, Apply) cover approval authority, controlled distribution, complete audit file contents, and retention/disposition per program and legal requirements.
  • Approval confirms technical completeness and process compliance—not a chance for auditees to veto evidence-based findings.
  • Distribution lists follow need-to-know, contractual, and confidentiality rules; uncontrolled email forwards create legal and commercial risk.
  • The audit file retains the plan, evidence/working papers, communications, report, responses, and related records so conclusions remain defensible.
  • Retention periods come from audit procedure, contracts, regulations, and records control—not from personal preference to delete awkward files early.
Last updated: August 2026

8.3 Approvals, Distribution & Audit File Retention (CQA BoK II.C.3 — Apply)

/practice/cqaPractice questions with detailed explanations

BoK II.C.3 sits at the Apply level: you must use defined procedures for finalizing, sending, and keeping audit records. Many real-world failures happen after excellent fieldwork—wrong approver, oversharing, missing working papers, or early deletion of files needed for legal or certification defense.


Approvals: who signs and what approval means

Approval confirms that the report meets program requirements for accuracy, completeness, fairness, and format. It is not a negotiation session for the auditee to remove inconvenient facts.

RoleTypical approval / review function
Lead auditorOwns technical content; ensures findings match evidence and exit communications; prepares final draft
Audit team membersConfirm accuracy of their sections/evidence as required by procedure
Audit program manager / client representativeApproves release per charter or contract; checks process compliance and sensitivity
Technical reviewer (if used)Independent review for clarity, criteria linkage, and tone—not rewriting facts without evidence
AuditeeUsually acknowledges receipt or provides factual correction of errors—not veto power over objective findings

Approval practices that hold up under challenge

  1. Defined authority matrix in the audit procedure (who can approve internal vs supplier vs certification-related reports).
  2. Version control—draft vs final clearly marked; only finals are distributed as the official result.
  3. Correction of factual errors (wrong part number, wrong date) before or immediately after issue, with controlled revision if already distributed.
  4. No trading findings for hospitality or commercial pressure. Escalate interference through the audit program.
  5. Electronic signatures / workflow meet the organization’s records and e-signature rules when used.

Scenario — improper approval demand.
A supplier quality director refuses to "approve" the report unless a major is deleted. Correct application: the report is approved by the customer’s audit authority / lead per procedure; the supplier receives the report and responds with CAPA. Acknowledgment of receipt is not the same as power to rewrite findings. Document the pressure in the file if it continues.

Scenario — factual correction.
The auditee shows that sample lot "L-229" was actually "L-228" and provides shipping records. If the nonconformity still stands on correct identity, revise the evidence citation; if the error invalidates the finding, withdraw or amend the finding under controlled revision and communicate the change to all prior recipients.


Distribution procedures

Distribution answers: Who gets the report, which version, by what channel, and under what confidentiality rules?

Distribution principleApplication
Need-to-knowLimit copies to client, auditee management, audit program, and others required by charter/contract/regulation
Controlled channelSecure portal, controlled email, or records system—not public chat or personal Gmail
Distribution list in the fileRecord recipients, date, version
MarkingConfidential / proprietary / controlled as required
Third-party limitsDo not forward supplier audit reports to unrelated competitors or public forums
Regulatory accessSome reports must be available to regulators or certification bodies on request—plan storage accordingly

Who typically receives what

RecipientUsually receives
Client (commissioning party)Full final report
Auditee managementFull final report (or agreed redacted form only if contract allows—rare for internal audits)
Audit program filesFinal + drafts as required + working papers
Certification body / regulatorAs required by scheme or law
Observers / guidesNot automatically; only if procedure says so
Public / marketingNot without authorization; audit reports are generally internal/confidential

Scenario — over-distribution.
An auditor posts a supplier audit PDF with pricing and process photos to a company-wide Teams channel "for learning." That violates need-to-know and may breach confidentiality clauses. Correct application: share anonymized lessons through the audit program if desired; keep the identifiable report on the controlled distribution list only.

Scenario — under-distribution.
Only the shop-floor supervisor gets the report; plant quality leadership never sees majors. CAPA stalls and management review lacks input. Correct application: distribute per matrix to roles that own response and governance, not only the people who hosted the tour.


Audit file contents

The audit file (package, dossier, engagement record) is the complete, retrievable set of records that makes the audit defensible and repeatable for follow-up. If challenged six months later—"Why did you raise that major?"—the file must answer without relying on memory.

Typical required contents (apply your procedure’s checklist)

CategoryExamples
Authorization & planningAssignment/engagement letter, audit plan, risk notes, team competence records as required
Criteria & referencesStandards list, procedures, contracts, previous audit reports used
CommunicationsNotices, agendas, opening/closing attendance, significant emails
Working papers / evidenceChecklists, sampling records, interview notes, document review notes, photo logs, data extracts
Findings developmentTeam meeting notes, severity rationale, draft finding matrix
Report packageDrafts as required, final report, approvals, distribution list
Post-reportResponses, CAPA references, verification records, closure notes (may continue into follow-up files)
Confidentiality / access logsWhen sensitive data or restricted areas were involved

What not to leave out.
People often file the pretty PDF and discard messy notes. Those notes are frequently the only place sample sizes, who said what (role, not gossip), and negative results live. Apply retention to working papers, not only the final report.

Scenario — incomplete file.
A certification auditor asks the internal program to show evidence behind a closed major. The folder has the final report and a CAPA form, but no sampling sheet or document identifiers. The organization cannot demonstrate the original nonconformity basis. Apply II.C.3: retain evidence records linked by finding ID.


Retention policy

Retention defines how long audit records are kept, in what medium, and how they are disposed. Sources of requirements include:

  • Audit program procedure / records control procedure.
  • ISO-based QMS document control and retention rules.
  • Contracts (customer right to review supplier audit history).
  • Regulatory retention (medical device, pharma, aerospace, nuclear, financial, etc.).
  • Legal hold / litigation suspension of destruction.
  • Certification body and accreditation rules for audit program records.
Retention practiceWhy it matters
Defined period (e.g., current year + N years; or life of product + X)Consistency and compliance
Medium & readabilityElectronic formats remain accessible; migrations planned
Security & access controlConfidential content protected for the full retention life
Disposition methodSecure destruction when eligible; record of destruction if required
Legal hold overrideDo not destroy records under hold even if calendar retention expired
Alignment with CAPA recordsFinding evidence may need to outlive a short "report-only" habit

Scenario — early deletion.
An auditor deletes working papers two weeks after the report "to save space," keeping only the summary PDF. Eighteen months later a product liability inquiry needs the sample evidence. Retention policy was seven years for quality records. The deletion was a procedure violation and a business risk. Apply the longer of applicable requirements; never invent a personal shorter schedule.

Scenario — cloud accounts.
Lead auditor stores the only copy of supplier audit files in a personal cloud drive and leaves the company. Apply organizational repositories with access transfer—personal silos are not a retention system.


End-to-end finalization workflow (Apply checklist)

  1. Complete technical content (findings, summary, OFIs, timelines) per 8.1–8.2.
  2. Perform internal team accuracy check.
  3. Route for approval under the authority matrix; resolve factual corrections.
  4. Freeze final version ID/date.
  5. Distribute per controlled list; record recipients.
  6. Assemble audit file (plan through report + evidence).
  7. Start response clock; log incoming CAPA against finding IDs.
  8. Maintain file through verification/closure per II.D follow-up processes.
  9. Retain for the required period; dispose only when eligible and not on hold.

Interfaces with later BoK topics

  • II.D Follow-up & closure: retention and file completeness enable CAPA verification.
  • I.E Ethics & confidentiality: distribution and file access are ethics in action.
  • IV.A Program management: approval matrices, metrics, and e-record rules are program-level controls auditors must apply on each engagement.
  • IV.A.10 Electronic records / cybersecurity: electronic audit files need integrity, access control, and backup—not informal chat exports as the system of record.

Exam focus: Apply the procedure

II.C.3 items often present a broken finalization step and ask for the correct action:

  • Auditee demands veto → refuse improper approval role; escalate.
  • Report emailed to entire company → recognize confidentiality/distribution failure.
  • Only PDF kept → identify incomplete audit file.
  • Records deleted early → apply retention / legal hold concepts.
  • Draft labeled as final and sent → version control / approval failure.

When answering, pick the option that follows controlled process, protects objectivity, and preserves traceability—not the option that is fastest or most comfortable for the auditee.

Test Your Knowledge

After receiving a final supplier audit report, the supplier’s plant manager refuses to "approve" it unless a major nonconformity is removed. What is the correct application of approval practice?

A
B
C
D
Test Your Knowledge

Which set best represents contents that should be retained in a complete audit file?

A
B
C
D
Test Your Knowledge

An auditor finishes a report and emails the full supplier audit package—including proprietary process details—to a general company distribution list "for training." What requirement is most clearly violated?

A
B
C
D
Test Your Knowledge

Quality records procedure requires audit working papers to be retained for seven years. The lead auditor deletes raw checklists two weeks after issuing the report to "reduce clutter," keeping only the summary report. What is the correct evaluation?

A
B
C
D