5.1 Sampling Plans, Checklists & Working Papers

Key Takeaways

  • Sampling plans define what will be examined, how much, and why—linking risk and materiality to method (random, stratified, judgmental, block) rather than browsing records ad hoc.
  • Checklists, log sheets, and forms structure fieldwork; they support consistency and coverage but never replace auditor judgment, interviews, or observation of actual practice.
  • Working papers are the audit’s evidence trail: they show plan, samples, evidence references, conclusions, and who did what—supporting the report and enabling review or follow-up.
  • Manual and electronic documentation each need controls for completeness, integrity, version control, confidentiality, and retention; e-tools do not remove the duty to retain objective evidence.
  • Apply-level CQA items test whether tools match purpose and risk—oversampling low risk, using checklists as scripts, or leaving undocumented samples are common exam traps.
Last updated: August 2026

5.1 Sampling Plans, Checklists & Working Papers (CQA BoK II.A.5 — Apply)

Quick Answer: Auditors apply sampling plans (what to sample, how much, method), checklists/log sheets/forms (structured prompts and records), and working papers (evidence packages that support conclusions). Documentation may be manual or electronic, but every tool must remain risk-based, complete enough for review, and free of unchecked bias. Tools organize work—they do not replace judgment, interviews, or observation.

Domain II (Audit Process) is the largest scored block on the CQA exam (~30%). Planning tools sit at the hinge between planning and performance: if sampling is vague, checklists are used as scripts, or working papers cannot reconstruct how a finding was formed, the audit loses defensibility. At the Apply level, stems ask you to choose or critique tools in realistic scenarios—not merely define them.


Why tools matter before the opening meeting

A solid plan answers why, what, and against what. Tools answer how evidence will be obtained and recorded:

Tool familyPrimary jobTypical failure mode
Sampling planSelect a defensible subset of population (lots, records, transactions, people, times)“We’ll look at some files” with no method, size, or risk link
Checklists / forms / log sheetsStructure questions, criteria prompts, and field notesTreating the checklist as the entire audit or as a pass/fail scorecard
Working papersPreserve plan, evidence, analysis, and conclusions for report and reviewUndated notes, missing sample IDs, conclusions without referenced evidence
Manual vs electronic mediaCapture, store, protect, and retrieve the aboveUncontrolled spreadsheets, shadow files, or lost paper binders

On exam items, if the stem emphasizes coverage without justification, look for a missing or weak sampling plan. If it emphasizes inconsistency across auditors or missed clauses, look for weak checklists/working papers. If it emphasizes integrity or retention, look at documentation media and controls.


Sampling plans: method, size, and rationale

A sampling plan (for audit use—not necessarily a formal acceptance-sampling table from Domain V) states:

  1. Population (e.g., all CAPAs closed in the last 12 months; all incoming lots for product family B; all operators on Line 3).
  2. Objective of the sample (conformity to procedure X; effectiveness of training; timely disposition of NCs).
  3. Method of selection.
  4. Size / intensity (how many, over what period, depth of each item).
  5. Rationale tied to risk, history, materiality, and prior findings.
  6. What will expand the sample (first nonconformity triggers more sampling; contradictory interview answers trigger deeper trace).

Common audit sampling methods

MethodHow selection worksWhen it fitsCaution
RandomEach unit has known chance of selectionHomogeneous populations; reduce selection biasNeeds a usable frame (list of IDs); random ≠ “whatever is handy”
StratifiedPopulation split by risk strata; sample within eachMixed risk (high/medium/low customers, sites, product classes)Strata must be meaningful; don’t under-sample high risk
Judgmental / directedAuditor selects based on risk, changes, complaints, historyRisk-based audits; for-cause; follow-up on weak areasBias risk—document why these items; don’t pretend it is statistical
Block / systematicEvery nth record; consecutive periods or lotsDetect patterns over time; process stabilityCan miss seasonal spikes if step size is unlucky
Discovery / exploratoryFollow anomalies; expand where risk appearsWhen population is poorly defined or red flags appearMust still document path; not a license for aimless wandering
100% / completeAll items in a small critical setSafety-critical releases; tiny populations; regulatory hold pointsExpensive; reserve for high consequence or small N

CQA distinction: Domain V later covers acceptance sampling (AQL, consumer/producer risk) more formally. For II.A.5, the exam focus is planning a sample that supports audit conclusions, not calculating OC curves. Still, do not invent statistical claims (“we are 95% confident…”) from a casual judgment sample.

Risk drives intensity

  • High risk / high impact: larger sample, more strata, more observation of live work, less reliance on “easy” records only.
  • Stable, low risk, strong history: smaller sample, still with a defined method.
  • New process, new product, new supplier, prior major NC: increase sample size or shift to judgmental focus on the weak link.

Scenario — CAPA effectiveness sample.
Purpose: verify effectiveness of 12 CAPAs closed after a customer complaint surge. Weak plan: “Review a few CAPAs.” Strong plan: population = 12 CAPAs; method = 100% for majors and high-severity customer issues (n=5), plus random sample of remaining (n=4 of 7); for each, sample implementation evidence (revised SOP, training records) and effectiveness evidence (post-implementation process metrics or recurrence data for 90 days). Expand if any effectiveness claim lacks data.

Scenario — supplier lot records.
Purpose: evaluate incoming inspection control for sterile packaging. Population: 180 lots received in 6 months. Method: stratified—all lots with prior supplier SCAR or near-miss (stratum H), plus random from clean lots (stratum L). Size: all of H (8 lots) + 15 of L. For each lot: COC, inspection record, disposition, and instrument calibration status for gages used. Rationale: prior defects clustered on one material grade.


Checklists, log sheets, and forms

Checklists

A checklist is a structured list of criteria-linked prompts—clauses, procedure steps, risk questions—used to guide interviews, document reviews, and observations. Good checklists:

  • Map to approved criteria (standard, contract, internal procedure)—not personal preference.
  • Leave room for evidence notes, sample IDs, and “N/A with reason.”
  • Are customized to purpose and scope (surveillance checklist ≠ full system checklist ≠ for-cause).
  • Support consistency across team members without freezing inquiry.

Misuse: reading checklist questions verbatim and marking Yes/No without verifying practice; skipping areas because “not on the list”; scoring audits as percentages of checklist ticks.

Log sheets and field forms

Form typeUseWhat to capture
Interview logWho, when, role, topicsName/role, date/time, key statements, evidence offered, follow-ups
Document review logControlled docs examinedDoc ID, rev, date range, conformity notes, gaps
Observation / tour formLive process watchingLocation, time, process step, what was observed vs procedure
Sample registerTrace sample selectionsPopulation, method, IDs selected, results, expansions
Finding draft formBuild nonconformities earlyRequirement, evidence, nature of failure, severity draft
Daily issues / parking lotScope, access, conflictsItem, owner, resolution needed before exit

Forms reduce lost notes and support working-paper completeness. They do not authorize the auditor to invent requirements.

Customizing vs generic templates

Generic ISO clause checklists are a starting point. Apply-level planning expects tailoring: product-line risks, prior audit history, regulatory focus, multi-site central functions, and remote vs on-site evidence methods. A team that uses last year’s full checklist for a narrow CAPA verification audit is tooling incorrectly relative to purpose.


Working papers: the evidence package

Working papers (audit documentation) are the organized records that show planning decisions, fieldwork, analysis, and the basis for conclusions and the report. They enable:

  • Lead auditor review of team work before the exit meeting.
  • Report drafting with cited evidence.
  • Follow-up audits and CAPA verification.
  • Defense of conclusions if challenged by auditee or client.
  • Program evaluation and lessons learned.

Minimum content expectations (practical exam model)

  1. Plan linkage — purpose, scope, criteria, schedule references.
  2. Sampling plan and actual samples examined.
  3. Evidence — what was seen/heard/recorded, with IDs, dates, locations.
  4. Analysis — comparison of evidence to criteria; classification of issues.
  5. Conclusions — conformity, nonconformity, OFI, not auditable (with reason).
  6. Identity trail — who prepared, who reviewed, dates, revisions.

Exam trap: A finding in the report that cannot be traced to working-paper evidence is a documentation failure even if the auditor “remembers” the conversation.

Manual vs electronic documentation

DimensionManual (paper)Electronic
StrengthsSimple in restricted areas; easy markup on floorSearchable; templates; remote collaboration; backup potential
WeaknessesLoss, illegibility, hard multi-site sharingVersion chaos, incomplete uploads, access control gaps
Controls neededUnique IDs, binding, custody, scan retention policyAccess rights, audit trail if required, backup, naming conventions, offline contingency
ConfidentialityLocked storage; controlled copiesEncryption, least privilege, secure transfer
IntegrityInk changes initialed; no silent white-out of evidenceControlled edits; preserve original evidence files

Hybrid reality: Many audits use electronic checklists on tablets plus photos or exports from the auditee’s eQMS. The principle is the same: evidence must remain attributable, legible, contemporaneous, original (or controlled copy), and accurate—the ALCOA-style integrity mindset used in regulated environments is a useful quality-auditor discipline even when the audit is not GxP-specific.

Scenario — electronic tool without working papers.
A team completes a cloud checklist with only Yes/No ticks and no sample IDs or evidence notes. The report cites three major nonconformities. The auditee challenges one finding. Without working papers that identify the batch records and the exact requirement text, the team cannot defend the conclusion. Tooling existed; documentation quality failed.


Putting tools together in planning

A coherent toolkit for a three-day process audit might look like:

  1. Risk-ranked process list → drives sample intensity.
  2. Sampling plan per process (records + people + observation windows).
  3. Custom checklist linked to criteria and known weak points.
  4. Sample register + interview logs as daily field tools.
  5. Working-paper index so the lead can review before the closing meeting.
  6. Secure repository (manual binder control or electronic folder with access list).

Exam traps (analyze carefully)

  1. Checklist = audit — False. Checklists guide; evidence and judgment conclude.
  2. Random sampling without a frame — Grabbing folders from a shelf is convenience sampling, not random.
  3. Statistical overclaim — Don’t imply AQL/confidence from a few judgment picks.
  4. Electronic equals controlled — Software alone does not guarantee completeness or retention.
  5. One-size sample — CAPA verification, surveillance, and initial system audits need different intensity and selection logic.
  6. Empty working papers — Conclusions without referenced evidence fail review and exam logic.
/practice/cqaPractice questions with detailed explanations

Key Takeaways

  • Sampling plans state population, method, size, and risk rationale—and when to expand.
  • Checklists and forms structure fieldwork; they never replace criteria-based judgment or observation of practice.
  • Working papers reconstruct the audit path from plan to conclusion for report, review, and follow-up.
  • Manual and electronic media both require integrity, confidentiality, version control, and retention discipline.
  • Apply-level items punish ad hoc sampling, checklist-only audits, and findings that cannot be traced to documented evidence.
Test Your Knowledge

An auditor plans a risk-based internal audit of complaint handling. Historical data show most severity-1 complaints involve Product Line A, while Lines B and C are stable. Which sampling approach best matches Apply-level planning for II.A.5?

A
B
C
D
Test Your Knowledge

During planning, a junior auditor proposes using last year’s full 120-item system checklist for a two-day CAPA verification audit of five closed major nonconformities. What is the best lead-auditor response?

A
B
C
D
Test Your Knowledge

Which working-paper set best supports a challenged nonconformity after the audit?

A
B
C
D
Test Your Knowledge

A team will use tablets and an eQMS export for most evidence, with paper notes in a cleanroom where devices are restricted. Which statement best reflects manual vs electronic documentation expectations?

A
B
C
D