5.3 Creating and Distributing the Audit Plan

Key Takeaways

  • The audit plan is built from planning inputs: purpose, scope, criteria, risk, logistics, team competence, sampling approach, and strategies—not invented on the opening day.
  • A complete plan typically covers objectives, scope/boundaries, criteria, dates/sites, team roles, schedule of activities, methods, working language, resources, safety/access notes, and report timing.
  • Creating the plan is a BoK Create-level skill: assemble and document a coherent plan that others can execute and that the client/auditee can prepare against.
  • Distribute the plan to the client and auditee in time for preparation; share appropriate detail with the audit team and other stakeholders per program rules and confidentiality.
  • Late, incomplete, or secret plans undermine logistics, evidence quality, and credibility; material mid-course changes should be communicated and re-approved when they affect purpose, scope, or resources.
Last updated: August 2026

5.3 Creating and Distributing the Audit Plan (CQA BoK II.A.7 — Create)

Quick Answer: Create the audit plan by synthesizing purpose, scope, criteria, risk, logistics, team assignments, sampling, and strategies into a documented schedule of who will audit what, when, where, and how. Distribute the plan to the client and auditee (and the audit team / other stakeholders as required) early enough for preparation, with confidentiality and authority respected. A plan is a communication and control tool—not a private checklist kept only in the lead auditor’s head.

BoK II.A.1–4 build planning fundamentals (process, auditor selection, pre-audit documents, logistics). II.A.5–6 add tools and strategies. II.A.7 is the Create moment: produce and share the audit plan that operationalizes all of that work.


What the audit plan is (and is not)

The audit plan isThe audit plan is not
An agreed roadmap for conducting the auditThe final audit report
A coordination document for client, auditee, and teamA substitute for working papers or evidence
A living document that can be updated with controlAn unchangeable ritual immune to risk signals
Scoped to this engagement’s purpose and boundariesA generic annual calendar alone (that is program-level planning)

Program schedules (which suppliers this year) differ from the engagement audit plan (how Tuesday’s supplier audit will run). CQA items about “the audit plan” in the process domain usually mean the engagement plan.


Inputs used to create the plan

Create-level work starts from planning information already gathered:

  1. Purpose / objectives — why the audit exists (surveillance, qualification, CAPA verification, for-cause, internal risk-based).
  2. Scope and boundaries — sites, processes, products, periods, exclusions.
  3. Criteria — standards, contracts, procedures, quality agreements, regulatory requirements.
  4. Risk and priority — history, complaints, changes, prior NCs, business impact.
  5. Pre-audit document review / gap notes — where to spend depth.
  6. Logistics — access, escorts, PPE, safety, IT/remote tools, cleanroom rules, language.
  7. Team competence and independence — who can cover which processes; conflicts of interest removed.
  8. Sampling plans and strategies — how evidence will be obtained (5.1–5.2).
  9. Resources and timing — days, shifts, report due dates, travel.
  10. Client instructions — confidentiality, distribution lists, special focus areas.

Scenario — synthesizing inputs into a plan.
Client: certify readiness for a new product line launch in 6 weeks. Scope: Plant 2 production and QC for Product N; design is out of scope (owned at HQ, separate audit). Criteria: ISO 13485 clauses applicable to production/QMS processes + internal SOPs + customer quality agreement. Risk: first production lots; new sterilization supplier. Logistics: cleanroom gowning training required Monday AM. Team: lead + process auditor with sterilization experience; former NPI manager excluded for independence. Sampling: first three production lots forward-traced; sterilization records 100% for those lots; observation of two changeovers. The created plan turns these inputs into a day-by-day agenda with named owners—not a vague “we’ll audit production sometime next week.”


Typical contents of an audit plan

Exact templates vary by organization and ISO 19011-style practice, but Create-level plans usually include:

Core identification

  • Audit identification / number, dates, locations (including remote platforms if any).
  • Client, auditee organization/contacts, audit team members and roles (lead, auditor, technical expert, observer, translator).
  • Audit type/context (internal, supplier, certification support, etc.) and objectives.
  • Scope statement with inclusions/exclusions and records period.
  • Criteria list (document titles/revisions or standard designations as appropriate).

Execution design

Plan elementWhy it matters
Activity scheduleOpening meeting, process blocks, shifts, closing meeting—maps people and rooms
Process / area assignmentsMatches competence; prevents double-booking escorts
Methods & strategiesInterviews, traces, observation windows, remote vs on-site
Sampling approach summarySignals intensity; helps auditee prepare record retrieval
Working language / interpretersAvoids communication failure mid-audit
ResourcesRooms, network access, PPE, escorts, eQMS accounts
Safety & securitySite rules, restricted areas, photo policy, data handling
ConfidentialityWhat may be shared with whom
Report timing & draft review rulesSets expectations for findings communication
Follow-up expectations (if known)CAPA windows at high level without pre-writing findings

Schedule example (illustrative)

TimeActivityLeadAuditee contact
Day 1 08:30Opening meetingLead auditorPlant manager / MR
Day 1 09:30Document control & training (vertical)Auditor ADoc control
Day 1 13:00Production process forward trace Lot N-01 + observationLead + AProduction supervisor
Day 2 08:00Sterilization & supplier controlsLeadQA / SQE
Day 2 13:00Complaint / CAPA interfaces for Product NAuditor AQA
Day 2 16:00Team caucus / evidence reviewTeam
Day 3 09:00Follow-up gaps / additional samplesTeamAs needed
Day 3 14:00Closing meetingLeadLeadership

Plans should be detailed enough to prepare but flexible enough to allow discovery expansion when risk appears—with communication rules for changes.


Creating the plan: practical sequence

  1. Confirm purpose, scope, criteria with the client (resolve conflicts early).
  2. Map processes and risks to available days; cut low-value activities before overloading the agenda.
  3. Assign auditors by competence and independence; name technical experts if needed.
  4. Embed tools and strategies (sampling summary, forward/backward plans, observation needs).
  5. Integrate logistics (PPE training time, badge access, night-shift observation if risk requires).
  6. Write the plan document in the program’s template; version and date it.
  7. Internal team review (lead checks coverage vs purpose; gaps fixed before external send).
  8. Distribute (next section); capture acknowledgments when required.
  9. Update controlled revisions if material changes occur; re-issue to the same distribution list.

Quality checks before distribution

  • Does every major scope element appear in the schedule or an explicit offline/desktop activity?
  • Are high-risk processes given adequate time and the right auditor?
  • Are opening and closing meetings scheduled with the right authority levels?
  • Are remote vs on-site methods explicit where hybrid?
  • Would a competent auditee know what records and people to prepare?

Distributing the audit plan

Who receives what

StakeholderTypical distributionWhy
Client (who commissioned the audit)Full plan or agreed summaryAuthority over purpose/resources; approval of approach
Auditee (organization being audited)Plan details needed to prepare access, people, recordsFair notice; logistics success; reduces ambush perception
Audit teamFull plan + working papers toolkitExecution consistency
Guides / escortsSchedule and area needsFlow of the day
Observers / regulators / consultantsOnly as authorized; often limitedConfidentiality and independence
Other sites / central functionsPortions that affect themMulti-site coordination

Fairness and effectiveness: Auditees should generally know when you will be in which area and what processes are in scope. That is not “teaching to the test”—it is professional audit practice. Surprise elements (if any) must still respect ethics, safety, and program rules; for-cause audits may share less tactical detail but still need access logistics communicated to appropriate contacts.

Timing

Distribute early enough for:

  • Scheduling the right process owners and shifts.
  • Retrieving records from archives or eQMS.
  • Arranging escorts, PPE, badges, and conference rooms.
  • Resolving conflicts (shutdown days, customer visits, system freezes).

Last-minute plans that arrive the night before a multi-department audit are a common root cause of delays, missing interviewees, and incomplete samples—exam scenarios often treat this as poor planning practice.

Medium and control

  • Use controlled channels (secure email, portal, documented transmittal).
  • Mark revision and date; supersede prior plans explicitly.
  • Apply confidentiality labels when the plan reveals sensitive scope (for-cause, potential regulatory exposure).
  • Keep distribution lists with the working papers.

Scenario — distribution failure.
Lead auditor emails the plan only to the plant manager and not to the Quality Management Representative who owns eQMS access. On Day 1, production is ready but document control cannot grant auditor accounts. Opening meeting time is burned on access. Create-level expectation: distribution includes all roles needed for preparation, not a single informal contact.

Scenario — client vs auditee.
For a second-party supplier audit, the client is the purchasing company; the auditee is the supplier. Both need the plan: client confirms scope against the purchase agreement; supplier prepares the line. Omitting the supplier until the team arrives undermines logistics and relationship credibility.


Changing the plan

Plans are living documents. Triggers for formal update and re-communication:

  • Scope or purpose change (client-approved).
  • Loss of an auditor or critical technical expert.
  • Site access denial or safety shutdown.
  • Material discovery that requires significant reallocation of days.
  • Shift from remote to on-site (or reverse) for key processes.

Minor sequence swaps inside the same day may be managed on site with the guide and noted in working papers. Material changes affecting objectives, boundaries, or reportability should be documented and distributed to client/auditee as appropriate—never silent.


Link to opening meeting and report

The opening meeting confirms the plan (or agreed changes), introductions, logistics, and communication channels. It is not the first time the auditee should see the agenda. The closing meeting and report should be traceable to what the plan said would be covered—and to documented changes—so conclusions match the engagement that was authorized.

Exam traps (analyze carefully)

  1. Plan = report: The plan is prospective; the report is results.
  2. Secret plan is stronger auditing: Withholding the plan from the auditee usually harms evidence logistics; it is not a substitute for independence.
  3. Template dump without risk: A generic agenda that ignores purpose, high-risk processes, and competence is not a created plan.
  4. Distribute only internally: Client and auditee need appropriate visibility for II.A.7.
  5. Never change the plan: Rigidity that ignores safety or critical discovery is poor practice; uncontrolled silent change is also poor practice.
  6. Confusing program schedule with engagement plan: Annual audit program calendars do not replace the detailed plan for a specific audit.
/practice/cqaPractice questions with detailed explanations

Key Takeaways

  • Create the engagement audit plan from purpose, scope, criteria, risk, logistics, team, sampling, and strategies.
  • Include identification, schedule, assignments, methods, resources, safety, confidentiality, and reporting expectations.
  • Distribute to client and auditee (and team/stakeholders) with enough lead time for preparation.
  • Control revisions; communicate material changes; keep distribution records with working papers.
  • The plan enables execution and credibility—it is not the audit report and not a secret weapon.
Test Your Knowledge

Which set of inputs is most appropriate when creating an engagement audit plan under BoK II.A.7?

A
B
C
D
Test Your Knowledge

A lead auditor finishes a detailed three-day supplier audit plan two weeks before the visit. Who should typically receive the plan for a second-party audit, and why?

A
B
C
D
Test Your Knowledge

Mid-audit, a safety shutdown closes the only production line in scope for two days. The team wants to shift to an off-site design audit at headquarters, which was explicitly excluded from the approved scope. What is the best Create/distribute response?

A
B
C
D
Test Your Knowledge

Which statement best distinguishes an engagement audit plan from related documents?

A
B
C
D