8.1 Report Development and Content

Key Takeaways

  • Report development (BoK II.C.1, Create) turns working-paper observations into findings by grouping related evidence, testing significance against criteria, and stating requirement, evidence, and consequence clearly.
  • A finding is a conclusion of nonconformity or major issue supported by objective evidence; an observation or OFI is not automatically a finding—severity and risk determine escalation.
  • Assign unique IDs to findings and tracked items so CAPA, verification, and management review can follow each issue without ambiguity.
  • Significance and severity rank findings by impact on product, process, system, customer, and regulatory risk—not by how loudly a process owner objects.
  • Exam trap: treating every negative note as a reportable finding, or writing findings that restate opinions without criteria and evidence.
Last updated: August 2026

8.1 Report Development and Content (CQA BoK II.C.1 — Create)

/practice/cqaPractice questions with detailed explanations

Audit reporting is not a typing exercise at the end of the week. It is the Create-level skill of turning fieldwork into a decision-ready record. The 2026 CQA Body of Knowledge (II.C.1) expects you to develop report content so management, the auditee, and later verifiers can understand what failed, why it matters, and how to track closure.


From working papers to report content

During fieldwork you collect observations: notes, photos references, interview summaries, sample results, and document citations. Those notes are not yet findings. Report development is the structured conversion:

StageWhat you holdWhat you produce
CollectionRaw notes, checklists, samplesWorking papers
AnalysisPatterns, confirmed nonconformitiesCandidate findings / OFIs
EvaluationRisk, severity, significance vs criteriaPrioritized finding set
DocumentationDraft report language + IDsReport content ready for summary and distribution

Scenario — grouping observations.
In three areas you note: (1) calibration sticker expired on a torque wrench used for final assembly; (2) the same tool’s certificate in the lab file shows last calibration 18 months ago against an annual requirement; (3) two units from that station failed torque audit yesterday. Separately they look like three notes. Grouped, they support one finding on control of measuring equipment (or process control of torque) with multi-source evidence. Do not write three diluted findings when one coherent nonconformity better reflects system failure.


What belongs in a finding

A finding (often a nonconformity statement) is a conclusion that a requirement was not met, supported by objective evidence. Strong findings are traceable, factual, and usable for CAPA. Weak findings are vague, judgmental, or unlinked to criteria.

Anatomy of a usable finding statement

ElementPurposeWeak exampleStronger example
Unique IDTracking across CAPA and follow-up"Issue A"NC-2026-0417-03
Criteria / requirementWhat should have been true"Poor calibration control"QMS §7.1.5 / Procedure CAL-02 §4.2 requires annual calibration of torque tools used for product acceptance
Objective evidenceWhat was observed / recorded"Tools looked old"Tool TW-17 used on Line 2 had sticker expired 2025-11-01; certificate dated 2024-10-12; CAL-02 §4.2 requires 12-month interval
Statement of nonconformityClear gap"Calibration is bad"Measuring equipment used for product acceptance was not maintained within the required calibration interval
Location / process / owner contextWhere it lives(missing)Final assembly Line 2; process owner Manufacturing; records in Metrology
Significance / risk noteWhy it matters"Important"High product risk: torque is a CTQ for joint integrity; recent failed audits on same station

Grouping rules that keep reports honest

  1. Same requirement, same process, related evidence → usually one finding with multiple examples.
  2. Different requirements or independent root causes → separate findings, even if found the same day.
  3. Systemic pattern across areas → elevate to system-level finding rather than a long list of identical local notes.
  4. Isolated minor slip with no risk escalation → may stay observation/OFI, not a formal NC, depending on program rules and criteria.

Scenario — do not over-split.
Five missing signatures on five training records for the same procedure, same department, same month, against a training procedure requiring documented authorization before independent work, is typically one finding with five examples—not five findings that inflate the count without adding management insight.

Scenario — do not under-split.
A missing CAPA effectiveness check and an unauthorized drawing revision are both quality-system issues, but they map to different criteria and different process owners. Keep them separate so CAPA ownership and verification stay clean.


Significance, severity, and risk

BoK II.C.1 expects you to develop content with an eye to significance. Programs use different labels (major/minor, critical/major/minor, high/medium/low), but the evaluation logic is consistent: impact × likelihood / detectability context, tied to product, customer, regulatory, and QMS integrity risk.

DimensionQuestions the auditor asksTypical upward drivers
Product / patient / user impactCould nonconforming product reach the customer?Safety characteristic, sterility, load-bearing, labeling for use
Process / system impactIs the control system broken or a single slip?Missing process, no records, ineffective CAPA chain
Regulatory / contractualDoes this breach a hard external requirement?Explicit standard shall, license condition, customer QMS clause
ExtentIsolated or widespread?Multiple sites, repeated samples, long duration
Detection failureDid internal controls miss it?Escaped through QC, audit, or management review

Severity is not politics. Auditee pushback, commercial sensitivity, or "first time we have seen this" does not downgrade a high-risk nonconformity. Conversely, a messy desk or a preferred wording dispute is not automatically major. Document the risk rationale in working papers and, where program rules require, in the report so later reviewers understand the ranking.

Classification patterns (exam-friendly)

Classification (example scheme)MeaningReport implication
Major / criticalSystemic breakdown or high risk to product/customer/complianceFront-loaded in summary; short response timeline; may affect certification recommendation
MinorRequirement not met; limited extent/risk; control still largely effectiveIncluded in findings; standard CAPA path
OFI / observationConformity exists but improvement opportunity, or evidence of risk without clear nonconformity under criteriaSeparate from nonconformities; no automatic NC CAPA unless program converts it

Always follow your audit program’s defined severity scheme and the criteria in scope. On third-party audits, scheme rules may prescribe major/minor definitions; on internal audits, the charter or procedure owns the labels.


Unique IDs for tracking

Every formal finding (and often every OFI the program tracks) needs a unique identifier. Without IDs, response packages, verification audits, and management review cannot close the loop.

ID practiceWhy it matters
Unique per audit + sequence (e.g., AUD-2408-NC-07)Prevents collisions across years and sites
Stable once issuedChanging numbers after draft distribution breaks CAPA links
Type prefix (NC, OFI, OBS)Separates obligatory CAPA from optional improvement
Cross-reference to working papersEvidence trail for challenges and verification
Link fields for CAPA numberReport ID ≠ CAPA ID; map both in the file

Scenario — tracking failure.
A report lists "Finding 3: training records incomplete" with no ID. Six months later, three CAPAs claim to address "training." The verification auditor cannot prove which evidence closed which issue. Correct practice: NC-2026-0312-03 maps to CAPA-884, with effectiveness evidence filed under both numbers.


Content that must stay out of findings

Creating good report content also means excluding items that destroy credibility:

  • Opinions without criteria ("culture is weak") unless framed as OFI with evidence of process symptoms and no forced nonconformity claim.
  • Personally identifying blame ("Jane ignored the SOP") instead of process/system wording.
  • Confidential commercial data not needed to substantiate the finding.
  • Unresolved uncertainties presented as facts—if evidence is incomplete, either collect more or do not elevate to finding.
  • Scope creep conclusions outside agreed criteria and purpose.

Practical build sequence (Create-level workflow)

  1. Inventory all potential issues from team working papers after daily debriefs / pre-exit consensus.
  2. Validate each candidate against criteria and objective evidence; drop or reclassify weak items.
  3. Group related items; split independent ones.
  4. Rate significance/severity/risk using the program scheme.
  5. Assign unique IDs and owners (auditee process areas, not "blame names").
  6. Draft finding statements in consistent format.
  7. Align with exit-meeting messages so the written report does not surprise the auditee with new majors.
  8. Hand off to section 8.2 structure (summary, prioritization, OFI separation, response timeline).

Scenario — exit alignment.
Exit meeting covered two minors on document control. The draft report later adds a major on data integrity never discussed. That is a process failure in report development: new high-severity content after exit without justified late evidence undermines fairness and may violate program procedure. If late evidence appears, reconvene communication with the auditee/client per procedure before locking the report.


Exam focus: Create, don’t just list

II.C.1 is a Create cognitive level. Expect stems that ask you to:

  • Choose the best-written finding from options (criteria + evidence + clear NC).
  • Decide whether to group or separate issues.
  • Select the correct severity given risk facts.
  • Identify the purpose of unique IDs.
  • Reject findings that are subjective or outside criteria.

When in doubt, ask: Can a competent stranger open CAPA, fix the right process, and verify closure from this text alone? If not, the report content is not finished.

Test Your Knowledge

During team debrief, auditors log three notes: expired calibration sticker on a torque tool in use, calibration certificate overdue by six months for the same tool, and two recent torque failures from that station. Against a procedure requiring annual calibration of tools used for product acceptance, how should report content typically be developed?

A
B
C
D
Test Your Knowledge

Which finding statement best meets Create-level report content expectations for CQA?

A
B
C
D
Test Your Knowledge

A nonconformity involves missing CAPA effectiveness checks on three closed high-risk complaints over nine months. Internal audit procedure classifies systemic breakdowns affecting customer safety feedback loops as major. The plant manager argues it should be minor because "no injuries occurred." What should drive severity in the report?

A
B
C
D
Test Your Knowledge

Why must formal findings carry unique identifiers in the developed report content?

A
B
C
D