8.3 Approvals, Distribution & Audit File Retention
Key Takeaways
- Final report steps (BoK II.C.3, Apply) cover approval authority, controlled distribution, complete audit file contents, and retention/disposition per program and legal requirements.
- Approval confirms technical completeness and process compliance—not a chance for auditees to veto evidence-based findings.
- Distribution lists follow need-to-know, contractual, and confidentiality rules; uncontrolled email forwards create legal and commercial risk.
- The audit file retains the plan, evidence/working papers, communications, report, responses, and related records so conclusions remain defensible.
- Retention periods come from audit procedure, contracts, regulations, and records control—not from personal preference to delete awkward files early.
8.3 Approvals, Distribution & Audit File Retention (CQA BoK II.C.3 — Apply)
/practice/cqaPractice questions with detailed explanations
BoK II.C.3 sits at the Apply level: you must use defined procedures for finalizing, sending, and keeping audit records. Many real-world failures happen after excellent fieldwork—wrong approver, oversharing, missing working papers, or early deletion of files needed for legal or certification defense.
Approvals: who signs and what approval means
Approval confirms that the report meets program requirements for accuracy, completeness, fairness, and format. It is not a negotiation session for the auditee to remove inconvenient facts.
| Role | Typical approval / review function |
|---|---|
| Lead auditor | Owns technical content; ensures findings match evidence and exit communications; prepares final draft |
| Audit team members | Confirm accuracy of their sections/evidence as required by procedure |
| Audit program manager / client representative | Approves release per charter or contract; checks process compliance and sensitivity |
| Technical reviewer (if used) | Independent review for clarity, criteria linkage, and tone—not rewriting facts without evidence |
| Auditee | Usually acknowledges receipt or provides factual correction of errors—not veto power over objective findings |
Approval practices that hold up under challenge
- Defined authority matrix in the audit procedure (who can approve internal vs supplier vs certification-related reports).
- Version control—draft vs final clearly marked; only finals are distributed as the official result.
- Correction of factual errors (wrong part number, wrong date) before or immediately after issue, with controlled revision if already distributed.
- No trading findings for hospitality or commercial pressure. Escalate interference through the audit program.
- Electronic signatures / workflow meet the organization’s records and e-signature rules when used.
Scenario — improper approval demand.
A supplier quality director refuses to "approve" the report unless a major is deleted. Correct application: the report is approved by the customer’s audit authority / lead per procedure; the supplier receives the report and responds with CAPA. Acknowledgment of receipt is not the same as power to rewrite findings. Document the pressure in the file if it continues.
Scenario — factual correction.
The auditee shows that sample lot "L-229" was actually "L-228" and provides shipping records. If the nonconformity still stands on correct identity, revise the evidence citation; if the error invalidates the finding, withdraw or amend the finding under controlled revision and communicate the change to all prior recipients.
Distribution procedures
Distribution answers: Who gets the report, which version, by what channel, and under what confidentiality rules?
| Distribution principle | Application |
|---|---|
| Need-to-know | Limit copies to client, auditee management, audit program, and others required by charter/contract/regulation |
| Controlled channel | Secure portal, controlled email, or records system—not public chat or personal Gmail |
| Distribution list in the file | Record recipients, date, version |
| Marking | Confidential / proprietary / controlled as required |
| Third-party limits | Do not forward supplier audit reports to unrelated competitors or public forums |
| Regulatory access | Some reports must be available to regulators or certification bodies on request—plan storage accordingly |
Who typically receives what
| Recipient | Usually receives |
|---|---|
| Client (commissioning party) | Full final report |
| Auditee management | Full final report (or agreed redacted form only if contract allows—rare for internal audits) |
| Audit program files | Final + drafts as required + working papers |
| Certification body / regulator | As required by scheme or law |
| Observers / guides | Not automatically; only if procedure says so |
| Public / marketing | Not without authorization; audit reports are generally internal/confidential |
Scenario — over-distribution.
An auditor posts a supplier audit PDF with pricing and process photos to a company-wide Teams channel "for learning." That violates need-to-know and may breach confidentiality clauses. Correct application: share anonymized lessons through the audit program if desired; keep the identifiable report on the controlled distribution list only.
Scenario — under-distribution.
Only the shop-floor supervisor gets the report; plant quality leadership never sees majors. CAPA stalls and management review lacks input. Correct application: distribute per matrix to roles that own response and governance, not only the people who hosted the tour.
Audit file contents
The audit file (package, dossier, engagement record) is the complete, retrievable set of records that makes the audit defensible and repeatable for follow-up. If challenged six months later—"Why did you raise that major?"—the file must answer without relying on memory.
Typical required contents (apply your procedure’s checklist)
| Category | Examples |
|---|---|
| Authorization & planning | Assignment/engagement letter, audit plan, risk notes, team competence records as required |
| Criteria & references | Standards list, procedures, contracts, previous audit reports used |
| Communications | Notices, agendas, opening/closing attendance, significant emails |
| Working papers / evidence | Checklists, sampling records, interview notes, document review notes, photo logs, data extracts |
| Findings development | Team meeting notes, severity rationale, draft finding matrix |
| Report package | Drafts as required, final report, approvals, distribution list |
| Post-report | Responses, CAPA references, verification records, closure notes (may continue into follow-up files) |
| Confidentiality / access logs | When sensitive data or restricted areas were involved |
What not to leave out.
People often file the pretty PDF and discard messy notes. Those notes are frequently the only place sample sizes, who said what (role, not gossip), and negative results live. Apply retention to working papers, not only the final report.
Scenario — incomplete file.
A certification auditor asks the internal program to show evidence behind a closed major. The folder has the final report and a CAPA form, but no sampling sheet or document identifiers. The organization cannot demonstrate the original nonconformity basis. Apply II.C.3: retain evidence records linked by finding ID.
Retention policy
Retention defines how long audit records are kept, in what medium, and how they are disposed. Sources of requirements include:
- Audit program procedure / records control procedure.
- ISO-based QMS document control and retention rules.
- Contracts (customer right to review supplier audit history).
- Regulatory retention (medical device, pharma, aerospace, nuclear, financial, etc.).
- Legal hold / litigation suspension of destruction.
- Certification body and accreditation rules for audit program records.
| Retention practice | Why it matters |
|---|---|
| Defined period (e.g., current year + N years; or life of product + X) | Consistency and compliance |
| Medium & readability | Electronic formats remain accessible; migrations planned |
| Security & access control | Confidential content protected for the full retention life |
| Disposition method | Secure destruction when eligible; record of destruction if required |
| Legal hold override | Do not destroy records under hold even if calendar retention expired |
| Alignment with CAPA records | Finding evidence may need to outlive a short "report-only" habit |
Scenario — early deletion.
An auditor deletes working papers two weeks after the report "to save space," keeping only the summary PDF. Eighteen months later a product liability inquiry needs the sample evidence. Retention policy was seven years for quality records. The deletion was a procedure violation and a business risk. Apply the longer of applicable requirements; never invent a personal shorter schedule.
Scenario — cloud accounts.
Lead auditor stores the only copy of supplier audit files in a personal cloud drive and leaves the company. Apply organizational repositories with access transfer—personal silos are not a retention system.
End-to-end finalization workflow (Apply checklist)
- Complete technical content (findings, summary, OFIs, timelines) per 8.1–8.2.
- Perform internal team accuracy check.
- Route for approval under the authority matrix; resolve factual corrections.
- Freeze final version ID/date.
- Distribute per controlled list; record recipients.
- Assemble audit file (plan through report + evidence).
- Start response clock; log incoming CAPA against finding IDs.
- Maintain file through verification/closure per II.D follow-up processes.
- Retain for the required period; dispose only when eligible and not on hold.
Interfaces with later BoK topics
- II.D Follow-up & closure: retention and file completeness enable CAPA verification.
- I.E Ethics & confidentiality: distribution and file access are ethics in action.
- IV.A Program management: approval matrices, metrics, and e-record rules are program-level controls auditors must apply on each engagement.
- IV.A.10 Electronic records / cybersecurity: electronic audit files need integrity, access control, and backup—not informal chat exports as the system of record.
Exam focus: Apply the procedure
II.C.3 items often present a broken finalization step and ask for the correct action:
- Auditee demands veto → refuse improper approval role; escalate.
- Report emailed to entire company → recognize confidentiality/distribution failure.
- Only PDF kept → identify incomplete audit file.
- Records deleted early → apply retention / legal hold concepts.
- Draft labeled as final and sent → version control / approval failure.
When answering, pick the option that follows controlled process, protects objectivity, and preserves traceability—not the option that is fastest or most comfortable for the auditee.
After receiving a final supplier audit report, the supplier’s plant manager refuses to "approve" it unless a major nonconformity is removed. What is the correct application of approval practice?
Which set best represents contents that should be retained in a complete audit file?
An auditor finishes a report and emails the full supplier audit package—including proprietary process details—to a general company distribution list "for training." What requirement is most clearly violated?
Quality records procedure requires audit working papers to be retained for seven years. The lead auditor deletes raw checklists two weeks after issuing the report to "reduce clutter," keeping only the summary report. What is the correct evaluation?