5.3 Creating and Distributing the Audit Plan
Key Takeaways
- The audit plan is built from planning inputs: purpose, scope, criteria, risk, logistics, team competence, sampling approach, and strategies—not invented on the opening day.
- A complete plan typically covers objectives, scope/boundaries, criteria, dates/sites, team roles, schedule of activities, methods, working language, resources, safety/access notes, and report timing.
- Creating the plan is a BoK Create-level skill: assemble and document a coherent plan that others can execute and that the client/auditee can prepare against.
- Distribute the plan to the client and auditee in time for preparation; share appropriate detail with the audit team and other stakeholders per program rules and confidentiality.
- Late, incomplete, or secret plans undermine logistics, evidence quality, and credibility; material mid-course changes should be communicated and re-approved when they affect purpose, scope, or resources.
5.3 Creating and Distributing the Audit Plan (CQA BoK II.A.7 — Create)
Quick Answer: Create the audit plan by synthesizing purpose, scope, criteria, risk, logistics, team assignments, sampling, and strategies into a documented schedule of who will audit what, when, where, and how. Distribute the plan to the client and auditee (and the audit team / other stakeholders as required) early enough for preparation, with confidentiality and authority respected. A plan is a communication and control tool—not a private checklist kept only in the lead auditor’s head.
BoK II.A.1–4 build planning fundamentals (process, auditor selection, pre-audit documents, logistics). II.A.5–6 add tools and strategies. II.A.7 is the Create moment: produce and share the audit plan that operationalizes all of that work.
What the audit plan is (and is not)
| The audit plan is | The audit plan is not |
|---|---|
| An agreed roadmap for conducting the audit | The final audit report |
| A coordination document for client, auditee, and team | A substitute for working papers or evidence |
| A living document that can be updated with control | An unchangeable ritual immune to risk signals |
| Scoped to this engagement’s purpose and boundaries | A generic annual calendar alone (that is program-level planning) |
Program schedules (which suppliers this year) differ from the engagement audit plan (how Tuesday’s supplier audit will run). CQA items about “the audit plan” in the process domain usually mean the engagement plan.
Inputs used to create the plan
Create-level work starts from planning information already gathered:
- Purpose / objectives — why the audit exists (surveillance, qualification, CAPA verification, for-cause, internal risk-based).
- Scope and boundaries — sites, processes, products, periods, exclusions.
- Criteria — standards, contracts, procedures, quality agreements, regulatory requirements.
- Risk and priority — history, complaints, changes, prior NCs, business impact.
- Pre-audit document review / gap notes — where to spend depth.
- Logistics — access, escorts, PPE, safety, IT/remote tools, cleanroom rules, language.
- Team competence and independence — who can cover which processes; conflicts of interest removed.
- Sampling plans and strategies — how evidence will be obtained (5.1–5.2).
- Resources and timing — days, shifts, report due dates, travel.
- Client instructions — confidentiality, distribution lists, special focus areas.
Scenario — synthesizing inputs into a plan.
Client: certify readiness for a new product line launch in 6 weeks. Scope: Plant 2 production and QC for Product N; design is out of scope (owned at HQ, separate audit). Criteria: ISO 13485 clauses applicable to production/QMS processes + internal SOPs + customer quality agreement. Risk: first production lots; new sterilization supplier. Logistics: cleanroom gowning training required Monday AM. Team: lead + process auditor with sterilization experience; former NPI manager excluded for independence. Sampling: first three production lots forward-traced; sterilization records 100% for those lots; observation of two changeovers. The created plan turns these inputs into a day-by-day agenda with named owners—not a vague “we’ll audit production sometime next week.”
Typical contents of an audit plan
Exact templates vary by organization and ISO 19011-style practice, but Create-level plans usually include:
Core identification
- Audit identification / number, dates, locations (including remote platforms if any).
- Client, auditee organization/contacts, audit team members and roles (lead, auditor, technical expert, observer, translator).
- Audit type/context (internal, supplier, certification support, etc.) and objectives.
- Scope statement with inclusions/exclusions and records period.
- Criteria list (document titles/revisions or standard designations as appropriate).
Execution design
| Plan element | Why it matters |
|---|---|
| Activity schedule | Opening meeting, process blocks, shifts, closing meeting—maps people and rooms |
| Process / area assignments | Matches competence; prevents double-booking escorts |
| Methods & strategies | Interviews, traces, observation windows, remote vs on-site |
| Sampling approach summary | Signals intensity; helps auditee prepare record retrieval |
| Working language / interpreters | Avoids communication failure mid-audit |
| Resources | Rooms, network access, PPE, escorts, eQMS accounts |
| Safety & security | Site rules, restricted areas, photo policy, data handling |
| Confidentiality | What may be shared with whom |
| Report timing & draft review rules | Sets expectations for findings communication |
| Follow-up expectations (if known) | CAPA windows at high level without pre-writing findings |
Schedule example (illustrative)
| Time | Activity | Lead | Auditee contact |
|---|---|---|---|
| Day 1 08:30 | Opening meeting | Lead auditor | Plant manager / MR |
| Day 1 09:30 | Document control & training (vertical) | Auditor A | Doc control |
| Day 1 13:00 | Production process forward trace Lot N-01 + observation | Lead + A | Production supervisor |
| Day 2 08:00 | Sterilization & supplier controls | Lead | QA / SQE |
| Day 2 13:00 | Complaint / CAPA interfaces for Product N | Auditor A | QA |
| Day 2 16:00 | Team caucus / evidence review | Team | — |
| Day 3 09:00 | Follow-up gaps / additional samples | Team | As needed |
| Day 3 14:00 | Closing meeting | Lead | Leadership |
Plans should be detailed enough to prepare but flexible enough to allow discovery expansion when risk appears—with communication rules for changes.
Creating the plan: practical sequence
- Confirm purpose, scope, criteria with the client (resolve conflicts early).
- Map processes and risks to available days; cut low-value activities before overloading the agenda.
- Assign auditors by competence and independence; name technical experts if needed.
- Embed tools and strategies (sampling summary, forward/backward plans, observation needs).
- Integrate logistics (PPE training time, badge access, night-shift observation if risk requires).
- Write the plan document in the program’s template; version and date it.
- Internal team review (lead checks coverage vs purpose; gaps fixed before external send).
- Distribute (next section); capture acknowledgments when required.
- Update controlled revisions if material changes occur; re-issue to the same distribution list.
Quality checks before distribution
- Does every major scope element appear in the schedule or an explicit offline/desktop activity?
- Are high-risk processes given adequate time and the right auditor?
- Are opening and closing meetings scheduled with the right authority levels?
- Are remote vs on-site methods explicit where hybrid?
- Would a competent auditee know what records and people to prepare?
Distributing the audit plan
Who receives what
| Stakeholder | Typical distribution | Why |
|---|---|---|
| Client (who commissioned the audit) | Full plan or agreed summary | Authority over purpose/resources; approval of approach |
| Auditee (organization being audited) | Plan details needed to prepare access, people, records | Fair notice; logistics success; reduces ambush perception |
| Audit team | Full plan + working papers toolkit | Execution consistency |
| Guides / escorts | Schedule and area needs | Flow of the day |
| Observers / regulators / consultants | Only as authorized; often limited | Confidentiality and independence |
| Other sites / central functions | Portions that affect them | Multi-site coordination |
Fairness and effectiveness: Auditees should generally know when you will be in which area and what processes are in scope. That is not “teaching to the test”—it is professional audit practice. Surprise elements (if any) must still respect ethics, safety, and program rules; for-cause audits may share less tactical detail but still need access logistics communicated to appropriate contacts.
Timing
Distribute early enough for:
- Scheduling the right process owners and shifts.
- Retrieving records from archives or eQMS.
- Arranging escorts, PPE, badges, and conference rooms.
- Resolving conflicts (shutdown days, customer visits, system freezes).
Last-minute plans that arrive the night before a multi-department audit are a common root cause of delays, missing interviewees, and incomplete samples—exam scenarios often treat this as poor planning practice.
Medium and control
- Use controlled channels (secure email, portal, documented transmittal).
- Mark revision and date; supersede prior plans explicitly.
- Apply confidentiality labels when the plan reveals sensitive scope (for-cause, potential regulatory exposure).
- Keep distribution lists with the working papers.
Scenario — distribution failure.
Lead auditor emails the plan only to the plant manager and not to the Quality Management Representative who owns eQMS access. On Day 1, production is ready but document control cannot grant auditor accounts. Opening meeting time is burned on access. Create-level expectation: distribution includes all roles needed for preparation, not a single informal contact.
Scenario — client vs auditee.
For a second-party supplier audit, the client is the purchasing company; the auditee is the supplier. Both need the plan: client confirms scope against the purchase agreement; supplier prepares the line. Omitting the supplier until the team arrives undermines logistics and relationship credibility.
Changing the plan
Plans are living documents. Triggers for formal update and re-communication:
- Scope or purpose change (client-approved).
- Loss of an auditor or critical technical expert.
- Site access denial or safety shutdown.
- Material discovery that requires significant reallocation of days.
- Shift from remote to on-site (or reverse) for key processes.
Minor sequence swaps inside the same day may be managed on site with the guide and noted in working papers. Material changes affecting objectives, boundaries, or reportability should be documented and distributed to client/auditee as appropriate—never silent.
Link to opening meeting and report
The opening meeting confirms the plan (or agreed changes), introductions, logistics, and communication channels. It is not the first time the auditee should see the agenda. The closing meeting and report should be traceable to what the plan said would be covered—and to documented changes—so conclusions match the engagement that was authorized.
Exam traps (analyze carefully)
- Plan = report: The plan is prospective; the report is results.
- Secret plan is stronger auditing: Withholding the plan from the auditee usually harms evidence logistics; it is not a substitute for independence.
- Template dump without risk: A generic agenda that ignores purpose, high-risk processes, and competence is not a created plan.
- Distribute only internally: Client and auditee need appropriate visibility for II.A.7.
- Never change the plan: Rigidity that ignores safety or critical discovery is poor practice; uncontrolled silent change is also poor practice.
- Confusing program schedule with engagement plan: Annual audit program calendars do not replace the detailed plan for a specific audit.
Key Takeaways
- Create the engagement audit plan from purpose, scope, criteria, risk, logistics, team, sampling, and strategies.
- Include identification, schedule, assignments, methods, resources, safety, confidentiality, and reporting expectations.
- Distribute to client and auditee (and team/stakeholders) with enough lead time for preparation.
- Control revisions; communicate material changes; keep distribution records with working papers.
- The plan enables execution and credibility—it is not the audit report and not a secret weapon.
Which set of inputs is most appropriate when creating an engagement audit plan under BoK II.A.7?
A lead auditor finishes a detailed three-day supplier audit plan two weeks before the visit. Who should typically receive the plan for a second-party audit, and why?
Mid-audit, a safety shutdown closes the only production line in scope for two days. The team wants to shift to an off-site design audit at headquarters, which was explicitly excluded from the approved scope. What is the best Create/distribute response?
Which statement best distinguishes an engagement audit plan from related documents?