2.3 Criteria: Standards, Contracts, Specs & QMS

Key Takeaways

  • Audit criteria are the set of policies, procedures, standards, regulations, contracts, specifications, and requirements used as the reference against which audit evidence is compared.
  • Valid criteria sources include external industry/national/international standards, contracts (including quality agreements), product/process specifications, organizational policies, and the internal QMS.
  • Auditor personal opinions, rumors, and another employer’s internal standards are not audit criteria for the engagement.
  • Criteria ≠ evidence ≠ findings: criteria are the yardstick, evidence is what was observed/collected, and findings are the comparison result (conformity, nonconformity, or OFI).
  • Quality agreements are a 2026 CQA emphasis: second-party audits often use signed quality agreements as primary contractual criteria defining roles, records, change notification, and acceptance requirements.
Last updated: August 2026

2.3 Audit Criteria — Standards, Contracts, Specs & QMS (CQA BoK I.C)

Quick Answer: Audit criteria are the policies, procedures, standards, regulations, contracts, specifications, and other requirements used as the reference against which audit evidence is compared. Sources include external standards, contracts and quality agreements, specifications, policies, and the internal QMS. Criteria ≠ evidence ≠ findings. The 2026 BoK emphasizes quality agreements as criteria—especially for second-party audits—while personal opinions never qualify as criteria.

If purpose says why and scope says where/what boundaries, criteria say against what rules the auditor judges conformity.


What Audit Criteria Are (and Are Not)

TermDefinitionExample
Audit criteriaReference requirements used for comparisonISO 9001:2015 clause on control of nonconforming outputs; SOP-QA-14 rev. C; quality agreement §4.2 defect limits
Audit evidenceRecords, statements of fact, or other verifiable information related to criteriaInterview notes, observed labeling, CAPA log extracts, photos of hold-tag use
Audit findingsResults of evaluating evidence against criteriaConformity, nonconformity (major/minor as defined), observation, OFI
Audit conclusionOutcome of an audit after considering objectives and findings“Capable supplier with two minor NCs” / “system not effectively implemented”

Rule: No criterion → no nonconformity. You may still note a risk or OFI, but you cannot fairly write “nonconforming” against a preference that was never a requirement.

Not criteria

  • Auditor’s personal opinions or “how we did it at my last company.”
  • Rumors from competitors or hallway gossip.
  • Unapproved draft procedures not yet effective (unless the audit is specifically of draft readiness and that is agreed).
  • Another organization’s proprietary standards not adopted by the auditee or contract.
  • Vague “industry best practice” with no adopted reference—unless a criterion explicitly requires current good practice and defines it.

Sources of Criteria

BoK I.C groups the practical universe of criteria into external standards, contracts (including quality agreements), specifications, policies, and internal QMS documentation. Real audits usually use a stack of these sources.

1. External standards (industry, national, international)

Examples:

  • International: ISO 9001 (QMS), ISO 13485 (medical devices), ISO/IEC 17025 (labs), ISO 14001 (environment), ISO 45001 (OH&S).
  • Industry / sector: IATF 16949 (automotive), AS9100 (aerospace), GFSI benchmarked schemes (food), etc.
  • National / regulatory: FDA QSR / QMSR expectations, EU MDR requirements, EPA rules, national electrical or building codes when quality/safety systems incorporate them.
  • Guidance may inform interpretation but is criteria only when adopted by regulation, contract, or the organization’s QMS as mandatory.

Certification audits primarily use the certification standard + the organization’s documented system. Internal audits often use the same stack plus internal procedures at greater depth.

2. Contracts and quality agreements (2026 emphasis)

Contracts establish enforceable requirements between parties: delivery, quality levels, right-to-audit, record retention, change notification, intellectual property, and acceptance criteria.

Quality agreements (also called quality technical agreements in some regulated sectors) are specialized contracts or contract annexes that allocate quality responsibilities between organizations—commonly manufacturer ↔ contract manufacturer, sponsor ↔ supplier, or brand owner ↔ co-packer.

Typical quality-agreement topicsWhy auditors care
Roles for release, testing, and deviation handlingClarifies who must do what—criteria for both parties
Change control and notification timelinesUnauthorized changes become contractual nonconformities
Record retention and right of accessSupports second-party evidence gathering
Complaint / adverse event communicationDefines speed and content of quality signals
Specifications and acceptance quality levelsProvides measurable product criteria
Data integrity / electronic system expectationsModern cyber-linked quality criteria
Sub-tier supplier controlsExtends requirements down the chain

Scenario — quality agreement as primary criteria.
A pharmaceutical sponsor conducts a second-party audit of a contract lab. ISO 17025 is useful context, but the signed quality agreement requires method-transfer protocols, predefined OOS investigation timelines, and 24-hour notification of invalid runs. The auditor finds scientifically interesting practices that still miss the 24-hour notification clause. Finding basis: quality agreement requirement, supported by email timestamps and investigation files (evidence).

The 2026 CQA BoK specifically elevates quality agreements as audit criteria, reflecting how much quality work now sits in multi-party networks. Expect exam items that contrast quality agreements (criteria) with observations (evidence).

3. Specifications

Specifications define required characteristics of products, materials, services, or processes: dimensions, purity, performance, labeling content, service-level response times, software requirements, etc. Specs may be customer drawings, internal finished-goods specs, pharmacopeial monographs, or service catalogs incorporated by contract.

Product/process audits lean heavily on specifications plus related work instructions. System audits still sample specification control—approval, revision, distribution, and use at point of work.

4. Policies

Policies are high-level management statements of intent and direction (quality policy, data-integrity policy, supplier policy, safety policy). They become audit criteria when they create commitments the organization must operationalize. Auditors test whether lower-level procedures and actual practices fulfill policy—not whether the policy poster is laminated.

5. Internal QMS documentation

The auditee’s own system is a primary criteria source:

  • Quality manual / documented information describing the system.
  • Procedures, process maps, work instructions.
  • Forms and templates when they define required fields/steps.
  • Quality objectives and KPI definitions when used as performance criteria.
  • Training matrices, calibration intervals, sampling plans defined by the organization.

Important: Organizations may set requirements stricter than an external standard. Exceeding the standard in a way that improves quality is not a nonconformity. Failing to meet their own stricter procedure is a nonconformity against QMS criteria, even if the external standard would have allowed less.


Stacking Criteria: Which Reference Wins?

Conflicts happen. A practical hierarchy used in many regulated and contractual settings:

  1. Law / regulation (cannot be contracted away).
  2. Customer contract / quality agreement / customer specs (as applicable).
  3. External voluntary standards adopted for certification or claim.
  4. Internal QMS requirements.
  5. Guidance / best practice (interpretive unless adopted).

When criteria conflict, auditors should not invent a private ranking. They identify the conflict as a system issue (document control / contract review failure) and evaluate against the governing requirement for the engagement’s purpose. Second-party audits often prioritize the contract and quality agreement for commercial quality obligations while still flagging regulatory noncompliance risks.


Criteria vs. Evidence vs. Findings — Exam Mastery

This triad is one of the highest-yield distinctions in Auditing Fundamentals.

Worked example

  • Criterion: Procedure CAL-01 requires torque wrenches used on final assembly to be calibrated every 6 months and labeled with due date.
  • Evidence: Three wrenches on Line 2 show due dates 9–14 months past; calibration database confirms no recalls; operators state they “still work fine.”
  • Finding: Nonconformity — control of monitoring and measuring resources / CAL-01 not effectively implemented. Objective evidence lists wrench IDs, locations, due dates, and database excerpts.
  • Not a valid finding alone: “I prefer monthly calibration” (opinion, no criterion).

Another example — positive practice

  • Criterion: ISO 9001 requires competent people; organization meets training requirements.
  • Evidence: In addition, the plant uses monthly competency drills beyond the procedure.
  • Finding: Conformity, with optional positive practice recognition—not a nonconformity for “exceeding the standard.”

Writing findings that survive challenge

Strong findings cite:

  1. The requirement (criteria citation).
  2. The objective evidence (what, where, how many, when).
  3. The gap (clear comparison statement).

Weak findings skip the criteria citation or generalize (“calibration is bad”) without evidence.


Criteria Across Audit Types

Audit contextDominant criteria sources
First-party internal auditInternal QMS + adopted external standards + applicable regs
Second-party supplier auditPurchase orders, quality agreements, customer specs, applicable standards
Third-party certificationCertification standard + organization’s documented system
Process auditProcess specs, control plans, work instructions, acceptance criteria
Product auditProduct specifications, drawings, inspection standards
CAPA verificationPrior finding, CAPA plan commitments, related procedures
For-causeRequirements relevant to the failure mode (often regs + procedures + specs)

Surveillance reuses certification criteria but samples a subset of processes; criteria do not disappear—coverage is cyclic.


Quality Agreements: Deep Dive for 2026 Items

Expect stems such as: “Quality agreements between organizations are primarily used as…” with the correct idea audit criteria for second-party (and sometimes internal verification of partner controls).

Auditor habits when quality agreements are criteria

  1. Obtain the effective agreement (signed, current revision) during planning—not only a generic ISO checklist.
  2. Extract auditable shalls: notification periods, approval rights, record lists, metrics, right-to-audit clauses.
  3. Map agreement clauses to processes (change control, testing, release, complaint handling).
  4. Sample both parties’ obligations when the audit scope includes dual responsibilities.
  5. Separate commercial negotiation from conformity: auditors report gaps; legal/commercial teams renegotiate terms.

Related 2026 criteria theme notes

Question-bank and BoK updates around 2026 also stress that social responsibility was removed from the criteria topic list in Auditing Fundamentals, while quality agreements, cybersecurity factors, and data integrity gained emphasis. For this section, anchor on quality agreements and the classic criteria sources; treat cyber/data integrity as criteria when policies, regs, or agreements impose them (linking to benefits in 2.2).


Common Criteria Errors on the Exam

ErrorWhy it fails
Using personal opinion as criteriaViolates objectivity; not a requirement
Citing a draft standard not adoptedNot an effective requirement for the auditee
Ignoring the quality agreement on a supplier auditMisses the primary commercial criteria stack
Writing NC for exceeding ISO minimumsStricter good practice is not nonconformity
Confusing evidence with criteria“I saw a red tag” is evidence; the hold procedure is criteria
Findings without criteria citationsCannot be defended; may be opinion in disguise
Auditing to a previous employer’s SOPsWrong organization, wrong criteria

Planning Implication: Criteria Drive Checklists

Checklists should trace to criteria, not to auditor memory. When criteria change—new standard revision, updated quality agreement, revised customer specs—plans and checklists must update. Sampling plans answer how much evidence; criteria answer what good looks like.

Opening meeting confirmation

Professionals confirm criteria with the auditee at the start: “We will evaluate against ISO 9001:2015, your QMS documented information, and Quality Agreement QA-17 rev. 4.” Surprises about the yardstick destroy trust and waste time.

Closing the loop

Every nonconformity in the report should allow a reader to answer: Which requirement? What evidence? What is the gap? If any answer is missing, the finding is not ready.


Key Exam Anchors

  • Criteria = requirements used as the reference for comparison.
  • Sources: external standards, contracts/quality agreements, specifications, policies, internal QMS.
  • Quality agreements are high-yield 2026 criteria for inter-organizational audits.
  • Criteria vs. evidence vs. findings is a mandatory mental model.
  • Personal opinion is never criteria; exceeding a standard is not automatic nonconformity.
Test Your Knowledge

Which of the following is NOT typically considered audit criteria?

A
B
C
D
Test Your Knowledge

Which item is an example of audit criteria rather than audit evidence?

A
B
C
D
Test Your Knowledge

Quality agreements between a manufacturer and a contract supplier are primarily used as:

A
B
C
D
Test Your Knowledge

An auditor observes a practice that exceeds ISO 9001 minimums and improves process control. The organization’s procedure and the standard are both met. How should this be treated?

A
B
C
D