2.3 Criteria: Standards, Contracts, Specs & QMS
Key Takeaways
- Audit criteria are the set of policies, procedures, standards, regulations, contracts, specifications, and requirements used as the reference against which audit evidence is compared.
- Valid criteria sources include external industry/national/international standards, contracts (including quality agreements), product/process specifications, organizational policies, and the internal QMS.
- Auditor personal opinions, rumors, and another employer’s internal standards are not audit criteria for the engagement.
- Criteria ≠ evidence ≠ findings: criteria are the yardstick, evidence is what was observed/collected, and findings are the comparison result (conformity, nonconformity, or OFI).
- Quality agreements are a 2026 CQA emphasis: second-party audits often use signed quality agreements as primary contractual criteria defining roles, records, change notification, and acceptance requirements.
2.3 Audit Criteria — Standards, Contracts, Specs & QMS (CQA BoK I.C)
Quick Answer: Audit criteria are the policies, procedures, standards, regulations, contracts, specifications, and other requirements used as the reference against which audit evidence is compared. Sources include external standards, contracts and quality agreements, specifications, policies, and the internal QMS. Criteria ≠ evidence ≠ findings. The 2026 BoK emphasizes quality agreements as criteria—especially for second-party audits—while personal opinions never qualify as criteria.
If purpose says why and scope says where/what boundaries, criteria say against what rules the auditor judges conformity.
What Audit Criteria Are (and Are Not)
| Term | Definition | Example |
|---|---|---|
| Audit criteria | Reference requirements used for comparison | ISO 9001:2015 clause on control of nonconforming outputs; SOP-QA-14 rev. C; quality agreement §4.2 defect limits |
| Audit evidence | Records, statements of fact, or other verifiable information related to criteria | Interview notes, observed labeling, CAPA log extracts, photos of hold-tag use |
| Audit findings | Results of evaluating evidence against criteria | Conformity, nonconformity (major/minor as defined), observation, OFI |
| Audit conclusion | Outcome of an audit after considering objectives and findings | “Capable supplier with two minor NCs” / “system not effectively implemented” |
Rule: No criterion → no nonconformity. You may still note a risk or OFI, but you cannot fairly write “nonconforming” against a preference that was never a requirement.
Not criteria
- Auditor’s personal opinions or “how we did it at my last company.”
- Rumors from competitors or hallway gossip.
- Unapproved draft procedures not yet effective (unless the audit is specifically of draft readiness and that is agreed).
- Another organization’s proprietary standards not adopted by the auditee or contract.
- Vague “industry best practice” with no adopted reference—unless a criterion explicitly requires current good practice and defines it.
Sources of Criteria
BoK I.C groups the practical universe of criteria into external standards, contracts (including quality agreements), specifications, policies, and internal QMS documentation. Real audits usually use a stack of these sources.
1. External standards (industry, national, international)
Examples:
- International: ISO 9001 (QMS), ISO 13485 (medical devices), ISO/IEC 17025 (labs), ISO 14001 (environment), ISO 45001 (OH&S).
- Industry / sector: IATF 16949 (automotive), AS9100 (aerospace), GFSI benchmarked schemes (food), etc.
- National / regulatory: FDA QSR / QMSR expectations, EU MDR requirements, EPA rules, national electrical or building codes when quality/safety systems incorporate them.
- Guidance may inform interpretation but is criteria only when adopted by regulation, contract, or the organization’s QMS as mandatory.
Certification audits primarily use the certification standard + the organization’s documented system. Internal audits often use the same stack plus internal procedures at greater depth.
2. Contracts and quality agreements (2026 emphasis)
Contracts establish enforceable requirements between parties: delivery, quality levels, right-to-audit, record retention, change notification, intellectual property, and acceptance criteria.
Quality agreements (also called quality technical agreements in some regulated sectors) are specialized contracts or contract annexes that allocate quality responsibilities between organizations—commonly manufacturer ↔ contract manufacturer, sponsor ↔ supplier, or brand owner ↔ co-packer.
| Typical quality-agreement topics | Why auditors care |
|---|---|
| Roles for release, testing, and deviation handling | Clarifies who must do what—criteria for both parties |
| Change control and notification timelines | Unauthorized changes become contractual nonconformities |
| Record retention and right of access | Supports second-party evidence gathering |
| Complaint / adverse event communication | Defines speed and content of quality signals |
| Specifications and acceptance quality levels | Provides measurable product criteria |
| Data integrity / electronic system expectations | Modern cyber-linked quality criteria |
| Sub-tier supplier controls | Extends requirements down the chain |
Scenario — quality agreement as primary criteria.
A pharmaceutical sponsor conducts a second-party audit of a contract lab. ISO 17025 is useful context, but the signed quality agreement requires method-transfer protocols, predefined OOS investigation timelines, and 24-hour notification of invalid runs. The auditor finds scientifically interesting practices that still miss the 24-hour notification clause. Finding basis: quality agreement requirement, supported by email timestamps and investigation files (evidence).
The 2026 CQA BoK specifically elevates quality agreements as audit criteria, reflecting how much quality work now sits in multi-party networks. Expect exam items that contrast quality agreements (criteria) with observations (evidence).
3. Specifications
Specifications define required characteristics of products, materials, services, or processes: dimensions, purity, performance, labeling content, service-level response times, software requirements, etc. Specs may be customer drawings, internal finished-goods specs, pharmacopeial monographs, or service catalogs incorporated by contract.
Product/process audits lean heavily on specifications plus related work instructions. System audits still sample specification control—approval, revision, distribution, and use at point of work.
4. Policies
Policies are high-level management statements of intent and direction (quality policy, data-integrity policy, supplier policy, safety policy). They become audit criteria when they create commitments the organization must operationalize. Auditors test whether lower-level procedures and actual practices fulfill policy—not whether the policy poster is laminated.
5. Internal QMS documentation
The auditee’s own system is a primary criteria source:
- Quality manual / documented information describing the system.
- Procedures, process maps, work instructions.
- Forms and templates when they define required fields/steps.
- Quality objectives and KPI definitions when used as performance criteria.
- Training matrices, calibration intervals, sampling plans defined by the organization.
Important: Organizations may set requirements stricter than an external standard. Exceeding the standard in a way that improves quality is not a nonconformity. Failing to meet their own stricter procedure is a nonconformity against QMS criteria, even if the external standard would have allowed less.
Stacking Criteria: Which Reference Wins?
Conflicts happen. A practical hierarchy used in many regulated and contractual settings:
- Law / regulation (cannot be contracted away).
- Customer contract / quality agreement / customer specs (as applicable).
- External voluntary standards adopted for certification or claim.
- Internal QMS requirements.
- Guidance / best practice (interpretive unless adopted).
When criteria conflict, auditors should not invent a private ranking. They identify the conflict as a system issue (document control / contract review failure) and evaluate against the governing requirement for the engagement’s purpose. Second-party audits often prioritize the contract and quality agreement for commercial quality obligations while still flagging regulatory noncompliance risks.
Criteria vs. Evidence vs. Findings — Exam Mastery
This triad is one of the highest-yield distinctions in Auditing Fundamentals.
Worked example
- Criterion: Procedure CAL-01 requires torque wrenches used on final assembly to be calibrated every 6 months and labeled with due date.
- Evidence: Three wrenches on Line 2 show due dates 9–14 months past; calibration database confirms no recalls; operators state they “still work fine.”
- Finding: Nonconformity — control of monitoring and measuring resources / CAL-01 not effectively implemented. Objective evidence lists wrench IDs, locations, due dates, and database excerpts.
- Not a valid finding alone: “I prefer monthly calibration” (opinion, no criterion).
Another example — positive practice
- Criterion: ISO 9001 requires competent people; organization meets training requirements.
- Evidence: In addition, the plant uses monthly competency drills beyond the procedure.
- Finding: Conformity, with optional positive practice recognition—not a nonconformity for “exceeding the standard.”
Writing findings that survive challenge
Strong findings cite:
- The requirement (criteria citation).
- The objective evidence (what, where, how many, when).
- The gap (clear comparison statement).
Weak findings skip the criteria citation or generalize (“calibration is bad”) without evidence.
Criteria Across Audit Types
| Audit context | Dominant criteria sources |
|---|---|
| First-party internal audit | Internal QMS + adopted external standards + applicable regs |
| Second-party supplier audit | Purchase orders, quality agreements, customer specs, applicable standards |
| Third-party certification | Certification standard + organization’s documented system |
| Process audit | Process specs, control plans, work instructions, acceptance criteria |
| Product audit | Product specifications, drawings, inspection standards |
| CAPA verification | Prior finding, CAPA plan commitments, related procedures |
| For-cause | Requirements relevant to the failure mode (often regs + procedures + specs) |
Surveillance reuses certification criteria but samples a subset of processes; criteria do not disappear—coverage is cyclic.
Quality Agreements: Deep Dive for 2026 Items
Expect stems such as: “Quality agreements between organizations are primarily used as…” with the correct idea audit criteria for second-party (and sometimes internal verification of partner controls).
Auditor habits when quality agreements are criteria
- Obtain the effective agreement (signed, current revision) during planning—not only a generic ISO checklist.
- Extract auditable shalls: notification periods, approval rights, record lists, metrics, right-to-audit clauses.
- Map agreement clauses to processes (change control, testing, release, complaint handling).
- Sample both parties’ obligations when the audit scope includes dual responsibilities.
- Separate commercial negotiation from conformity: auditors report gaps; legal/commercial teams renegotiate terms.
Related 2026 criteria theme notes
Question-bank and BoK updates around 2026 also stress that social responsibility was removed from the criteria topic list in Auditing Fundamentals, while quality agreements, cybersecurity factors, and data integrity gained emphasis. For this section, anchor on quality agreements and the classic criteria sources; treat cyber/data integrity as criteria when policies, regs, or agreements impose them (linking to benefits in 2.2).
Common Criteria Errors on the Exam
| Error | Why it fails |
|---|---|
| Using personal opinion as criteria | Violates objectivity; not a requirement |
| Citing a draft standard not adopted | Not an effective requirement for the auditee |
| Ignoring the quality agreement on a supplier audit | Misses the primary commercial criteria stack |
| Writing NC for exceeding ISO minimums | Stricter good practice is not nonconformity |
| Confusing evidence with criteria | “I saw a red tag” is evidence; the hold procedure is criteria |
| Findings without criteria citations | Cannot be defended; may be opinion in disguise |
| Auditing to a previous employer’s SOPs | Wrong organization, wrong criteria |
Planning Implication: Criteria Drive Checklists
Checklists should trace to criteria, not to auditor memory. When criteria change—new standard revision, updated quality agreement, revised customer specs—plans and checklists must update. Sampling plans answer how much evidence; criteria answer what good looks like.
Opening meeting confirmation
Professionals confirm criteria with the auditee at the start: “We will evaluate against ISO 9001:2015, your QMS documented information, and Quality Agreement QA-17 rev. 4.” Surprises about the yardstick destroy trust and waste time.
Closing the loop
Every nonconformity in the report should allow a reader to answer: Which requirement? What evidence? What is the gap? If any answer is missing, the finding is not ready.
Key Exam Anchors
- Criteria = requirements used as the reference for comparison.
- Sources: external standards, contracts/quality agreements, specifications, policies, internal QMS.
- Quality agreements are high-yield 2026 criteria for inter-organizational audits.
- Criteria vs. evidence vs. findings is a mandatory mental model.
- Personal opinion is never criteria; exceeding a standard is not automatic nonconformity.
Which of the following is NOT typically considered audit criteria?
Which item is an example of audit criteria rather than audit evidence?
Quality agreements between a manufacturer and a contract supplier are primarily used as:
An auditor observes a practice that exceeds ISO 9001 minimums and improves process control. The organization’s procedure and the standard are both met. How should this be treated?