1.1 Product, Process, System, Hybrid & Remote Audits
Key Takeaways
- A product (or service) audit evaluates a finished item or delivered service against specifications; a process audit evaluates how work is performed; a system audit evaluates interacting processes against a management-system standard
- Desk (questionnaire-based) audits collect documentary evidence without on-site presence and are often used for supplier screening or pre-audit preparation
- Department, function, and element audits slice the organization by unit, cross-cutting activity, or standard clause rather than by end-to-end process
- Integrated (combined/joint) audits examine multiple management systems or share one audit team across parties; hybrid audits mix on-site and remote methods; remote audits use ICT without physical presence
- Exam trap: hybrid describes delivery method mix, not party relationship; remote is a modality, not a substitute for independence or for system scope
Why audit type matters on the CQA exam
ASQ CQA 2026 BoK I.A.1 expects you to analyze audit types—not merely memorize names. Scenario stems rarely say "this is a process audit." They describe what the auditor examines, what evidence is gathered, and what decision the client needs. Your job is to match that description to the correct type and to reject look-alike distractors.
Think in three dimensions every time:
- Object of evaluation — product/service, process, element/clause, or whole management system
- Organizational slice — one department, one function across units, or the full system
- Delivery method — fully on-site, desk/questionnaire, remote via ICT, hybrid mix, or multi-system/joint arrangements
Those dimensions are independent. You can run a remote process audit of a single supplier line, or an on-site integrated system audit covering quality and environmental management together. Confusing dimensions is a common exam trap.
Product and service audits
A product audit evaluates a finished good (or defined intermediate product) against applicable requirements—drawings, specs, acceptance criteria, labeling, packaging, and sometimes configuration or lot documentation. Evidence is often attributes and variables data on the item itself: dimensional checks, visual inspection, functional test results, certificate of analysis, and traceability marks.
A service audit is the service-sector counterpart: the "product" is the delivered service (call handling, clinical encounter, logistics handoff). Auditors sample service events, observe delivery, review tickets or records, and compare outcomes to service-level agreements or work instructions.
When used: Incoming inspection escalation, end-of-line quality gates, customer returns analysis, release readiness, or when management needs independent confirmation that outputs conform—regardless of how well procedures look on paper.
Limitation: A conforming product sample does not prove the process is stable or that the QMS is effective. It answers "Did this item meet requirements?" more than "Can the system keep producing conforming items?"
Scenario
An auditor pulls 20 finished infusion pumps from finished goods, verifies software version labels, runs a functional checklist, and reviews DHR completeness for those serial numbers. That is a product audit, even if the auditor also glances at a procedure—because the primary object is the product and its associated product records.
Process audits
A process audit examines how work is performed: inputs, activities, controls, resources, measurements, and outputs for a defined process (for example, sterilization, complaint handling, change control, or order-to-cash). Classic tools include process maps, turtle diagrams, SIPOC, and forward/backward tracing of a transaction or lot through the process.
Evidence emphasizes activity and control effectiveness: work instructions in use, skill of operators, equipment status, in-process checks, reaction plans when limits are hit, and handoffs to adjacent processes.
When used: After a defect trend, when a process is high-risk or newly changed, to verify training effectiveness, or when management wants depth on one value stream without auditing every QMS clause.
Exam contrast — process vs system: A process audit is deep and narrow (one process, rich evidence). A system audit is broad and interaction-focused (many processes, how they link to policy, objectives, and standard requirements). If the stem says "follow one lot from receiving through shipping," lean process. If it says "evaluate the QMS against ISO 9001 clauses organization-wide," lean system.
Desk (questionnaire-based) audits
A desk audit (also called a document or questionnaire-based audit) gathers evidence without on-site presence, typically via completed questionnaires, submitted procedures, records samples, and remote document review. It is not the same as a full remote audit that includes live interviews and virtual process observation—though both avoid the facility floor.
When used: Supplier pre-qualification screens, triage before deciding on an on-site second-party audit, internal readiness checks, or low-risk surveillance when documentary evidence is sufficient and risk is acceptable.
Limitation: You cannot reliably verify implementation, culture, or floor-level practice from documents alone. Desk audits are powerful for screening and planning, weak as the sole method for high-risk processes.
Department, function, and element audits
These types define scope by organizational structure or standard structure, not by product flow.
| Type | Scope focus | Typical evidence |
|---|---|---|
| Department | One organizational unit (e.g., Receiving, QC Lab) | Local procedures, training matrices, department records, interviews in that unit |
| Function | A cross-cutting activity (e.g., training, calibration, document control) across departments | Function-owned procedures, samples from multiple areas using the function |
| Element | One clause or requirement set of a standard (e.g., ISO 9001 design controls, CAPA) | Clause criteria mapped to practices and records organization-wide or in selected areas |
When used: Internal audit programs often rotate element or function coverage across the year so every clause and critical function is covered without auditing the entire system every quarter. Department audits help when a unit owns many risks or has performance problems.
Trap: An element audit of "internal audit" or "management review" is still an audit of that requirement area—it is not automatically a system audit unless scope covers the interacting system as a whole.
System and management audits
A system audit evaluates the management system as a set of interacting processes against a defined standard or criteria set (ISO 9001, IATF 16949, internal QMS, etc.). Focus includes policy deployment, process interactions, risk-based thinking, performance monitoring, internal audit, CAPA, and management review—not only local compliance.
A management audit emphasizes whether management practices and controls achieve intended results: leadership commitment, resource provision, decision quality, and system effectiveness. In practice, many "management system audits" blend both ideas; on the exam, prefer system audit when the stem stresses conformity of the QMS to a standard, and management audit when the stem stresses evaluation of management effectiveness and control of the organization.
When used: Certification, re-certification, major change after restructuring, or when leadership needs assurance that the system—not just one process—is fit for purpose.
Integrated (combined / joint) audits
Integrated arrangements save disruption and reveal cross-system issues:
- Combined audit: One audit team audits two or more management systems together (e.g., quality + environmental + safety) against integrated criteria or multiple standards in one engagement.
- Joint audit: Two or more auditing organizations cooperate to audit a single auditee (for example, two certification bodies or a customer and a registrar coordinating logistics).
When used: Organizations with integrated management systems (IMS), multi-standard certifications, or customers seeking efficiency. Plan carefully so criteria, sampling, and reporting remain clear for each standard or party.
Hybrid and remote audits
| Method | Definition | Best use |
|---|---|---|
| Remote | Audit activities performed at a location other than the auditee's site using ICT (video, secure file share, live data systems) | Document review, interviews, system walkthroughs of electronic records; pandemic or access constraints; low-to-moderate risk when ICT risk is controlled |
| Hybrid | Mix of on-site and remote activities in one audit plan | High-risk floor processes on-site + document/system reviews remote; multi-site programs |
Remote and hybrid are modalities, not party types and not substitutes for audit purpose. A remote third-party surveillance audit is still third-party and still surveillance; only the location of evidence collection changed.
ICT risks to plan: identity of interviewees, confidentiality, inability to observe informal workarounds, sample integrity, and connectivity. If critical processes cannot be verified remotely, expand on-site scope—that is still a valid hybrid design.
Comparison table: scope, focus, and evidence
| Audit type | Primary scope | Primary focus | Dominant evidence |
|---|---|---|---|
| Product / service | Defined product or service samples | Conformity of outputs | Inspection/test results, product/service records |
| Process | Named process / value stream | Effectiveness of process controls | Observations, traces, in-process data, interviews |
| Desk / questionnaire | Documents and responses | Documentary readiness / risk screen | Questionnaires, submitted records |
| Department | One org unit | Local conformity and control | Unit records and interviews |
| Function | Cross-unit function | Function performance everywhere it touches | Multi-area samples of that function |
| Element | Standard clause(s) | Conformity to specific requirements | Clause-mapped evidence |
| System | Full management system | Interactions, conformity, effectiveness | Multi-process sampling vs criteria |
| Management | Leadership & management controls | Management effectiveness | Objectives, reviews, resource decisions |
| Integrated (combined) | Multiple standards/systems | Cross-system conformity | Multi-criteria evidence set |
| Joint | One auditee, multiple audit orgs | Coordinated assurance | Shared plan; separate or joint reports as agreed |
| Remote | Same object as planned; off-site ICT | Same as planned type | Electronic records, video, remote interviews |
| Hybrid | Same object; mixed locations | Same as planned type | Blend of on-site observation + remote review |
Exam traps (analyze carefully)
- Process vs system: Depth on one workflow ≠ system audit. Breadth across interacting QMS processes with standard criteria = system audit.
- Hybrid vs remote: Remote = entirely (or predominantly) off-site ICT. Hybrid = both on-site and remote methods in the plan. Hybrid is not "customer + registrar" and not "quality + EHS."
- Product audit ≠ process capability study: Product audits check conformity of items; they do not automatically establish statistical process control.
- Desk audit ≠ third-party certification audit by default: Party relationship is a separate BoK topic (I.A.2). A desk audit can be first-, second-, or third-party.
- Element audit of one clause is not automatically "integrated." Integrated refers to multiple systems/standards or joint audit organizations.
Key Takeaways
- Classify every audit by what is audited, which slice of the organization, and how evidence is collected.
- Product/service → outputs; process → how work runs; system → interacting management system against criteria.
- Desk audits screen with documents; remote and hybrid change delivery, not independence or purpose.
- Integrated means multi-system (combined) or multi-auditor-organization (joint)—not "a little of everything."
An auditor follows a single production lot from material receipt through final packaging, interviewing operators at each step and verifying in-process controls against the work instructions. Which audit type best describes this engagement?
A certification body plans video interviews, secure screen-share of the electronic QMS, and remote review of CAPA records, with no visit to the manufacturing floor. How should this modality be classified?
Which statement correctly distinguishes a process audit from a system audit?
Management wants one engagement that evaluates both the ISO 9001 quality system and the ISO 14001 environmental system with a single audit team and a unified schedule. Which label fits best?