12.4 Quality Review of Audit Documentation & Report Approval

Key Takeaways

  • Quality review is a systematic check of audit working documents, findings, and the draft report before the report is issued and the certification decision is made.
  • The audit team leader performs the first-line review of the team's working papers and findings, and the certification body performs an independent technical review before certification.
  • Under ISO/IEC 17021-1 the certification decision must be taken by a person or committee that did not participate in the audit, which is the structural safeguard against self-review.
  • The review tests traceability, sufficiency, correct clause referencing, consistent grading across the team, and consistency between the findings, the report narrative, and the recommendation.
  • Quality review protects the auditee too: it is the point at which a wrongly graded or poorly worded nonconformity is corrected before it reaches the client.
Last updated: September 2026

12.4 Quality Review of Audit Documentation & Report Approval

PECB requires the auditor to be able to conduct quality reviews of audit documentation and to know the guidelines and best practices to complete audit working documents and perform a quality review. This is the control that stands between the audit team's work and a certification decision, and it is the last opportunity to catch an error before it becomes an issued certificate.


1. Why Quality Review Exists

An audit produces a conclusion that a third party will rely on. Between the evidence and the certificate sit several failure modes that only review reliably catches:

  • Findings not traceable to evidence — a nonconformity statement with no supporting working paper.
  • Inconsistent grading across the team — auditor A grades an isolated lapse as major; auditor B grades a systemic failure as minor. Inconsistency is unfair to the auditee and indefensible on appeal.
  • Wrong clause referenced — the evidence describes a management-of-change failure but the finding cites Clause 8.1.1 rather than 8.1.3, making the corrective action target the wrong process.
  • Scope not covered — a process in the audit plan was never actually audited, and nobody noticed.
  • Report inconsistent with the findings — a narrative describing "a mature and effective system" sitting above three major nonconformities.
  • Overstated assurance — language claiming legal compliance or absolute safety.
  • Confidentiality breaches — named individuals' health data or a competitor's commercially sensitive information reproduced in a report with wide circulation.

2. The Two Levels of Review

First-line: the audit team leader

Performed before the closing meeting, while the team is still on site and evidence can still be obtained. ISO 19011 makes the team leader responsible for the conduct of the audit and for the audit report, and the daily audit team meeting is the natural forum.

The team leader:

  • Reviews each team member's working papers against the audit plan to confirm the planned scope was covered.
  • Tests each draft finding for traceability to specific, identified evidence.
  • Harmonises grading across the team so like is treated as like.
  • Checks clause references against the evidence described.
  • Consolidates duplicate findings — the same root failure raised separately by two auditors becomes one finding.
  • Resolves diverging opinions within the team, and records the reasoning.
  • Confirms that any unresolved diverging opinion with the auditee is recorded.

Doing this before the closing meeting matters: a finding withdrawn or re-graded after being presented to the client damages the audit's credibility, and evidence gaps can no longer be filled once the team has left site.

Second-line: independent technical review by the certification body

Performed after the report is submitted and before the certification decision. This is a requirement of ISO/IEC 17021-1:2015, and its defining feature is independence:

The certification decision must be made by a person or persons who did not participate in the audit.

This is the structural safeguard against self-review — the same logic that prohibits an internal auditor from auditing their own work under Clause 9.2, applied at the certification body level.

The technical reviewer checks:

  • Auditor and team competence for the scope and sector, including any technical expert used.
  • Audit duration against the certification body's own criteria (informed by IAF mandatory documents) — an audit completed suspiciously quickly is a red flag.
  • Completeness of the report and coverage of the audit plan.
  • That findings are supported, correctly graded, and correctly referenced.
  • That the recommendation follows logically from the findings.
  • For major nonconformities, that corrective action has been implemented and verified — verification of effectiveness, not merely receipt of a plan.
  • That scope wording on the proposed certificate accurately reflects what was audited.

3. A Practical Review Checklist

DimensionQuestionFailure signal
TraceabilityCan every finding be traced to a specific working paper identifying what, when, who, criterion, conclusion?"Permits — OK"
SufficiencyIs the evidence enough to support the grading applied?A major nonconformity resting on one interview
AppropriatenessIs the evidence relevant and from a reliable source?A finding built solely on verbal evidence
Clause accuracyDoes the cited clause actually contain the requirement breached?8.1.1 cited for a change-management failure
Grading consistencyAre comparable failures graded the same across the team?Two similar lapses, one major and one minor
CoverageWas every process in the audit plan actually audited?A plan line with no corresponding working paper
ObjectivityDoes the statement describe evidence, not opinion or accusation?"Management is indifferent to safety"
Report consistencyDoes the narrative match the findings and the recommendation?"Effective system" above three majors
Assurance languageIs the conclusion framed on a sample basis?"The site is compliant with all legislation"
ConfidentialityIs personal, health, or commercially sensitive data appropriately protected?Named individuals' medical results in the report
TimelinessWas the report issued within the agreed period?Report issued weeks late, findings stale

Writing quality that review should enforce

Each nonconformity statement should contain the requirement, the evidence, and the deviation — and nothing else. Review should strike:

  • Solutions. "The organization should purchase interlock guards." Specifying the remedy compromises impartiality and would make the auditor a consultant, barred from later auditing their own advice.
  • Accusations of intent. "Records were deliberately falsified." Intent is escalated as an irregularity, not asserted in a finding.
  • Personal criticism. Findings address processes, not named individuals' competence or character.
  • Vagueness. "Training records were generally poor" cannot be acted on. "Of 12 sampled contractor welders, 5 had no valid qualification evidence" can.

4. Quality Review Protects the Auditee

It is worth stating plainly, because candidates often read review as a control on the auditee. It is not — it is a control on the audit. Review is where a nonconformity graded major by an inexperienced auditor is correctly re-graded as minor before it reaches the client and triggers unnecessary cost and delay; where an ambiguous statement is sharpened so the auditee knows exactly what to fix; where a finding resting on one interview is either evidenced properly or withdrawn.

Worked example. A lead auditor reviews her team's output on the final evening of a Stage 2 audit and finds:

  1. Two findings, one cause. Auditor A raised a minor against Clause 7.2 (contractor competence records incomplete); auditor B raised a minor against Clause 8.1.4 (subcontractor evaluation not performed). Both trace to the same failure to operate the subcontractor verification process. The team leader consolidates them into a single major nonconformity against 8.1.4, cross-referencing 7.2, because the consolidated evidence shows a systemic process failure rather than two isolated lapses.
  2. An untraceable finding. Auditor C's draft states "emergency arrangements inadequate" with no working paper reference. The team leader sends auditor C back that evening to identify the specific evidence. He returns with two undated drill records and confirmation that the assembly point was relocated in January without the plan being updated. The finding is rewritten against Clause 8.2 with that evidence, and the underlying Clause 8.1.3 management-of-change gap noted.
  3. A solution embedded in a finding. A draft reads "the organization should appoint a full-time safety officer". Struck — it prescribes a remedy and exceeds the auditor's role.
  4. Overstated report language. The draft conclusion reads "the site operates safely and complies with all applicable legislation". Rewritten to conclude, on the basis of the samples examined, on conformity with ISO 45001:2018 and the effectiveness of the management system.

All four corrections happen before the closing meeting. The client receives findings that are consolidated, evidenced, actionable, and defensible — and the certification body's independent reviewer receives a file it can rely on.

Loading diagram...
The Two-Level Review Chain from Working Paper to Certificate
Test Your Knowledge

Under ISO/IEC 17021-1, who must take the certification decision after an audit report has been submitted?

A
B
C
D
Test Your Knowledge

During first-line review the team leader finds that auditor A raised a minor nonconformity on incomplete contractor competence records and auditor B raised a separate minor on subcontractor evaluation, both tracing to the same failure to operate the subcontractor verification process. What is the correct action?

A
B
C
D
Test Your Knowledge

A draft nonconformity statement reads: "Emergency arrangements are inadequate; the organization should appoint a full-time safety officer to address this." Which two defects should quality review correct?

A
B
C
D
Congratulations!

You've completed this section

Continue exploring other exams