2.4 Audit Planning, Execution & Reporting

Key Takeaways

  • Audit preparation requires establishing audit scope, criteria, schedule, team assignments, document review, and customized audit checklists.
  • Objective evidence must be collected through triangulation: interviewing personnel, reviewing documented records, and observing physical operations.
  • Audit sampling involves balancing judgmental (purposive) and statistical sampling techniques while recognizing the inherent risk of missing nonconformities.
  • A well-written nonconformance statement contains three elements: Statement of Fact (the observed condition), Objective Evidence (specific records/samples), and Standard Requirement (the clause violated).
Last updated: July 2026

2.4 Audit Planning, Execution & Reporting

The audit process requires a disciplined, phase-gate lifecycle to ensure objective evaluation, audit repeatability, and actionable reporting. The audit lifecycle comprises three major operational phases: Phase 1: Planning and Preparation, Phase 2: On-Site Execution, and Phase 3: Reporting, Closing, and Follow-Up.


1. Phase 1: Audit Planning and Preparation

Effective audit execution begins well before setting foot in the auditee's facility. Thorough preparation ensures efficiency, minimizes operational disruption, and establishes audit rigor.

Key Preparation Steps

  1. Define Audit Scope and Criteria:
    • Scope: Boundaries of the audit (physical locations, departments, product lines, date ranges).
    • Criteria: Standards, requirements, manuals, procedures, or contracts against which evidence is compared (e.g., ISO 9001:2015 Clause 8.5).
  2. Audit Team Selection: Lead Auditor assigns audit team members based on technical competence, sector expertise, and freedom from conflicts of interest.
  3. Document Review: Review auditee's QMS documentation (Quality Manual, SOPs, past audit findings, recent metrics) to identify risk areas.
  4. Audit Plan Creation: Formal document detailing audit objectives, schedule, locations, interviewed roles, and team assignments.
  5. Checklist Development: Preparing memory joggers and structured prompts.

Checklist Architecture: Benefits and Pitfalls

Checklists serve as essential memory aids for auditors, ensuring complete coverage of criteria.

  • Advantages: Ensures systematic coverage of all standard clauses; maintains consistency across multiple auditors; assists in time management.
  • Pitfalls: Can create "tunnel vision" if auditors strictly follow questions without pursuing unexpected lines of investigation; may reduce spontaneous open-ended questioning.
  • Questioning Techniques: Effective checklists utilize open-ended questions based on the 5Ws and H (Who, What, When, Where, Why, and How), avoiding closed yes/no prompts.

2. Phase 2: On-Site Execution & Evidence Collection

The Opening Meeting

The audit begins with a formal opening meeting led by the Lead Auditor. Key agenda items:

  • Introduction of audit team and auditee management.
  • Confirmation of audit objectives, scope, criteria, and schedule.
  • Confirmation of communication channels, escort roles, and safety/security protocols.
  • Explanation of audit sampling methodology and nonconformance classification.

Objective Evidence Collection (Triangulation)

Auditors must base all findings solely on objective evidence—verifiable qualitative or quantitative information, records, or statements of fact. Evidence is gathered using triangulation:

  1. Interviews: Asking open-ended questions to operators and staff at points of use.
  2. Observation: Physically observing operational setups, environmental conditions, calibration status tags, and material handling.
  3. Record Verification: Examining historical Travelers, SPC charts, calibration logs, and inspection sheets to confirm executed procedures match verbal claims.

Audit Sampling Techniques & Risk

Because inspecting 100% of records or parts is cost-prohibitive, auditors utilize sampling:

  • Judgmental (Purposive) Sampling: Auditors select samples based on professional judgment, historical risk areas, high-complexity parts, or newly hired operators.
  • Statistical Random Sampling: Utilizing probability-based sampling tables (e.g., ANSI/ASQ Z1.4) to draw representative samples across large record populations.
  • Sampling Risk: The risk that an audit sample does not represent the population, leading an auditor to conclude a system is compliant when major nonconformities exist (or vice versa).

Example Sampling Risk Scenario

An auditor samples $n = 10$ Device History Records out of a total population of $N = 1,000$ completed orders. If the actual true defect rate in the population is $p = 2%$, the probability of selecting zero nonconforming records in a random sample is given by the binomial distribution:

P(X=0)=(1p)n=(10.02)10=(0.98)100.817(81.7%)P(X = 0) = (1 - p)^n = (1 - 0.02)^{10} = (0.98)^{10} \approx 0.817 \quad (81.7\%)

Thus, there is an $81.7%$ probability that the audit sample will miss the defect entirely, highlighting why auditors must combine statistical sampling with targeted risk-based judgmental sampling.


3. Phase 3: Nonconformance Reporting, Closing & Follow-Up

Classifying Audit Findings

Auditors categorize findings into three distinct levels:

  1. Major Nonconformance: A total absence or complete breakdown of a required QMS system clause, or a condition that directly results in shipping nonconforming or hazardous product. (e.g., Complete lack of calibration system for measuring equipment).
  2. Minor Nonconformance: An isolated, single lapse in adherence to a documented procedure that does not jeopardize product safety or overall QMS integrity. (e.g., A single uncalibrated micrometer found on a bench where calibrated backup tools are actively used).
  3. Opportunity for Improvement (OFI): A condition that is currently compliant with standards but presents an operational vulnerability or efficiency enhancement opportunity.

The 3-Part Nonconformance Statement Structure

To be actionable, every formal Nonconformance Report (NCR) written by an auditor must contain three mandatory elements:

  1. Statement of Fact: Concise description of the nonconforming condition observed.
  2. Objective Evidence: Specific document numbers, serial numbers, tool IDs, and quantities.
  3. Standard Requirement: Exact standard clause or SOP section violated.

Example Nonconformance Statement

"During inspection of Work Center 4 (Statement of Fact), micrometer tool #MC-402 was found in active use past its calibration due date of April 15, 2026 (Objective Evidence). This violates ISO 9001:2015 Clause 7.1.5.2, which requires monitoring and measuring resources to be calibrated or verified at specified intervals (Standard Requirement)."

The Closing Meeting and Follow-Up Lifecycle

  • Closing Meeting: Held with auditee management to present audit findings, clarify misunderstandings, present the draft report, and establish formal timelines for Corrective Action Plan (CAPA) submission.
  • Follow-Up Verification: The audit is not closed until the auditor reviews root cause analysis, evaluates proposed CAPAs, and verifies implementation effectiveness (via document review or follow-up re-audit).
Loading diagram...
End-to-End Audit Lifecycle Flowchart
Test Your Knowledge

What are the three mandatory components required in a complete, audit-compliant Nonconformance Statement?

A
B
C
D
Test Your Knowledge

An auditor notices that out of 50 calibrated torque wrenches in an aerospace facility, a single torque wrench has an expired calibration sticker but is stored in a locked, red-tagged 'OUT OF SERVICE' cabinet. How should the auditor classify this observation?

A
B
C
D
Test Your Knowledge

An auditor samples 10 inspection logs from a total population of 500 logs using random sampling. What term describes the risk that the sample fails to uncover a system nonconformance present in the population?

A
B
C
D