13.2 Quality Reviews of Audit Records
Key Takeaways
- Audit records (notes, checklists, evidence references, NC statements, reports) must be complete, accurate, clear, and traceable from criteria → evidence → finding → conclusion.
- Quality review — by the Lead Auditor, peer, or CB technical reviewer — checks consistency, grading, confidentiality, and whether benefit-of-the-doubt decisions are documented.
- Weak records (vague NCs, missing sample descriptions, undated notes) undermine certification decisions and fail ISO 19011 / ISO/IEC 17021-1 expectations for reliable reporting.
- Retain or dispose of audit records per programme, contractual, legal, and confidentiality rules; drafts and personal notes are still sensitive.
- Before issue, verify report metadata, finding wording, auditee acknowledgment logistics, and that OFIs are not silently re-labeled as NCs (or the reverse).
13.2 Quality Reviews of Audit Records
Quick Answer: Quality review of audit records verifies that working papers and the audit report are complete, accurate, clear, and traceable — criteria linked to evidence, findings worded so the auditee can act, and conclusions defensible to a certification body. ISO 19011 expects proper retention/disposal; ISO/IEC 17021-1 expects CB review before certification decisions.
Even strong fieldwork fails if the record cannot support the conclusion. Domain 5 tests whether you know what "good audit records" look like, who reviews them, and how poor documentation creates risk for the auditee, the audit team, and the CB.
1. What Counts as Audit Records
Audit records are broader than the final PDF report. Typical EMS audit record set includes:
| Record type | Purpose | Quality risk if weak |
|---|---|---|
| Audit plan & scope | Defines boundaries and criteria | Findings outside scope or missing high-risk processes |
| Checklists / notes | Capture samples, interviews, observations | No traceability; "trust me" conclusions |
| Evidence references | Point to documents, photos, measurements | Unverifiable claims; confidentiality breaches if mishandled |
| Nonconformity reports | State requirement, evidence, gap | Auditee cannot correct; CB cannot grade |
| Audit report | Communicates conclusions | Misleading certification input |
| Communications | Opening/closing, clarification emails | Disputes about what was agreed |
Personal shorthand is fine during the day; by report issue, notes must be interpretable by another competent auditor or reviewer. If only the original author can decode them, the quality bar is not met.
2. Traceability: The Core Quality Test
A reviewer should be able to walk this chain without guessing:
- Criterion cited (ISO 14001 clause, legal obligation, or documented EMS requirement)
- Evidence collected (what, where, when, sample size / selection basis)
- Evaluation (conformity, NC, OFI, or inconclusive / limitation)
- Finding text (for NCs: clear statement of the gap)
- Conclusion / grading (major/minor per programme rules; effect on certification recommendation)
Breaks in the chain are classic review findings against the audit team:
- NC cites "poor environmental culture" with no clause or evidence
- Notes say "waste OK" with no sample description for a high-risk hazardous-waste area
- Report grades a major, but working papers show a single administrative typo
- Benefit-of-the-doubt closure has no note that the missing certificate was later produced and verified
Exam tip: Traceability protects both fairness to the auditee and integrity of the certificate.
3. Who Performs Quality Reviews — and When
During the audit (Lead Auditor / team)
Daily team meetings are the first quality gate. The Lead Auditor reviews draft NCs for criteria linkage, evidence strength, and consistent grading across auditors. Conflicting judgments are reconciled with evidence, not egos.
Before report release (Lead Auditor accountability)
Under ISO 19011, the Lead Auditor is responsible for the audit report's content. That includes ensuring team inputs are consolidated, confidential information is handled correctly, and open items are statused per programme rules.
Certification body technical review (third-party)
ISO/IEC 17021-1 requires that certification decisions are made by personnel who were not part of the audit team, based on a review of audit conclusions and supporting information. Your records must stand alone: a reviewer who was not on site should understand why each NC exists and why conformity was concluded elsewhere.
Peer or programme review (internal / supplier audits)
Internal audit programmes often require independent review of reports before management review input. Supplier EMS audits may require buyer QA review. The quality criteria are the same: clarity, evidence, consistency.
4. Quality Checklist for Nonconformity and Report Content
Before you call records "done," stress-test them:
Nonconformity quality
- Requirement quoted or precisely referenced (not paraphrased into auditor opinion)
- Evidence factual, dated, and specific ("Manifest #1847 dated 12 Mar 2026 missing transporter signature" beats "waste paperwork issues")
- Gap logical (reader sees how evidence fails the requirement)
- Grading justified (systemic vs isolated; effect on EMS intended outcomes)
- Not mixing multiple unrelated gaps into one unworkable NC — or, conversely, artificially splitting one systemic failure to hide severity
Report quality
- Objectives, scope, criteria, client, auditee, dates, team identified
- Summary of findings and conclusions aligned with working papers
- Unresolved issues / limitations stated honestly (including where evidence remained inconclusive)
- Confidentiality and distribution controls observed
- OFIs clearly labeled so they are not treated as NCs in corrective-action systems
Language quality Avoid absolute claims you did not verify ("full legal compliance achieved") unless the audit objective and evidence truly support them. Prefer precise statements: "Within the sample examined, operational controls for solvent storage met the documented procedure and observed conditions."
5. Common Record Defects That Fail Reviews
- Copy-paste criteria errors — wrong clause numbers (e.g., citing 8.2 for an operational-control failure that belongs under 8.1).
- Evidence theater — long quotations from procedures with no test of implementation.
- Invisible sampling — no explanation why those five effluent results or three contractors were chosen.
- Grade drift — identical lapse graded minor in Plant A and major in Plant B without rationale.
- Orphan OFIs — text that is clearly a requirement failure labeled "OFI" to avoid conflict (integrity failure).
- Over-collection of sensitive data — unnecessary personal data or proprietary process detail retained beyond need.
- Version chaos — final report disagrees with the NC log issued at closing.
Any of these can trigger CB queries, delayed certification decisions, or audit-programme nonconformities against the auditors.
6. Retention, Confidentiality, and Disposal
Quality review includes lifecycle control of records:
- Retain audit records for the period required by the audit programme, CB procedures, contracts, and applicable law (often years, not weeks).
- Protect confidentiality of auditee information — draft notes, photos of processes, and permit data are sensitive.
- Dispose securely when retention ends; do not leave unmarked USB drives or email archives uncontrolled.
- Own the boundary: report ownership typically sits with the audit client; team members follow programme rules on what they may keep personally.
Lead Auditors should confirm before the engagement how records will be stored (CB platform, client portal, encrypted share) and brief the team — quality includes information security hygiene, not only finding wording.
7. Linking Record Quality to Benefit of the Doubt
Sections 13.1 and 13.2 connect directly. When you apply benefit of the doubt, the record must show:
- What evidence was missing or conflicting
- What additional evidence was sought and the result
- Why an NC was not raised
- Any residual audit limitation communicated in the report
Silent leniency (no NC and no notes) fails quality review as badly as an unsupported NC. The defensible auditor leaves a trail that a technical reviewer can follow to the same professional judgment.
8. Practical Pre-Issue Review Routine
A compact Lead Auditor routine before releasing EMS audit records:
- Re-read each NC aloud as if you were the process owner receiving it.
- Spot-check three conformity areas: do notes show real sampling?
- Confirm majors/minors match programme definitions and site risk.
- Align closing-meeting slides / NC list with the draft report.
- Strip or protect sensitive attachments not required for the decision file.
- Verify names, dates, sites, and standard editions (ISO 14001:2015) are correct.
- Sign off only when another competent reviewer could defend the file.
Mastering this routine is as examinable as knowing Clause 6.1.2 — certification credibility rests on both the fieldwork and the record.
What is the primary purpose of a certification body's technical review of EMS audit records under ISO/IEC 17021-1?
Which nonconformity statement best meets audit-record quality expectations?
A Lead Auditor closed a potential finding after the auditee produced a missing monitoring log, but the working papers only say 'OK now.' Why is this a record-quality problem?
Which action BEST improves the quality of EMS audit records before report release?