Section 4.3: Preparing the Audit Plan and Working Documents (Checklists)
Key Takeaways
- The Audit Plan is the lead auditor's operational blueprint, detailed schedule, and resource allocation map sent in advance to the auditee.
- Audit checklists are working documents that act as memory aids, ensure standard coverage, and record audit sample trails.
- Process-based checklists (e.g. using Turtle Diagrams) evaluate interactions and effectiveness, aligning with ISO 9001:2015 process focus.
- Clause-by-clause checklists verify compliance with standard details but risk promoting a rigid check-the-box audit style.
- Auditors must avoid the 'checklist trap' by keeping checklists flexible and actively following audit trails based on gathered evidence.
Preparing the Audit Plan and Working Documents
Once the Stage 1 readiness review has confirmed that the organization's Quality Management System (QMS) is mature enough to proceed, the lead auditor must transition to detailed operational planning. This phase involves two primary tasks: developing a comprehensive Audit Plan and preparing the working documents, most notably the audit checklists. Effective planning ensures that the onsite Stage 2 audit is executed efficiently, covers all critical processes, and utilizes the audit team's collective expertise to gather valid, objective evidence.
Developing the Audit Plan (ISO 19011 Clause 6.3.2)
The audit plan is the operational blueprint for the audit. It is prepared by the lead auditor and serves as a communication tool to set expectations between the audit team and the auditee. Under ISO 19011:2018 guidelines, the audit plan should be flexible enough to permit changes as the audit progresses, but structured enough to ensure all objectives are met.
The audit plan must contain the following essential elements:
- Audit objectives, scope, and criteria: Reconfirming the parameters established during the initiation phase.
- Locations and schedules: Dates, locations (physical and virtual), and specific times for audit activities, including scheduled interviews and site tours.
- Audit team roles: Specific assignments for each auditor, identifying which processes, clauses, or locations they are responsible for auditing.
- Schedule of meetings: Specific times for the opening meeting, daily debriefs, audit team meetings, and the closing meeting.
- Allocation of resources: Ensuring that complex or high-risk processes (such as design control or special manufacturing processes) are allocated sufficient time and experienced auditors.
- Confidentiality and safety protocols: Statements outlining security restrictions, personal protective equipment (PPE) requirements, and confidentiality agreements.
The lead auditor must submit the audit plan to the auditee well in advance of the onsite activities. This allows the auditee to review the schedule, ensure that key personnel (process owners) are available, and request adjustments if there are operational conflicts.
Preparing Working Documents and Checklists (ISO 19011 Clause 6.3.4)
Working documents are the tools the audit team uses to facilitate the audit and record evidence. These documents include sampling plans, forms for recording findings (such as nonconformity reports), and audit checklists.
The audit checklist is the most critical working document. A well-designed checklist:
- Acts as a memory aid to ensure no critical requirements are overlooked.
- Helps manage audit time, keeping the auditor focused on the plan.
- Provides a consistent structure across the audit team.
- Serves as a record of what was audited, including sample sizes and document numbers.
However, checklists carry a significant risk: the Checklist Trap. If an auditor follows a checklist too rigidly, they may develop "tunnel vision," focusing only on the pre-written questions and failing to follow important "audit trails" (visual or document clues that suggest a systemic issue). Checklists must be used as a flexible guide, not a rigid script.
Process-Based vs. Clause-by-Clause Checklists
Auditors generally design checklists using one of two approaches:
- Clause-by-Clause Approach: This checklist is organized sequentially by the clauses of ISO 9001:2015 (e.g., Clause 4, then 5, then 6).
- Advantage: Easy to ensure that every single "shall" in the standard is checked.
- Disadvantage: Tends to create a disjointed audit that does not reflect how work flows through the organization. It promotes a check-the-box compliance focus rather than evaluating process effectiveness.
- Process-Based Approach: This checklist is designed around the organization's actual business processes (such as Purchasing, Operations, Design). It aligns with the "Process Approach" mandated by ISO 9001:2015.
- Advantage: Follows the natural flow of work, allowing the auditor to evaluate process interactions, efficiency, and the Plan-Do-Check-Act (PDCA) cycle.
- Disadvantage: Requires a more skilled and experienced auditor to design and execute.
To structure process-based checklists, lead auditors often use the Turtle Diagram method, which prompts the auditor to investigate six aspects of a process: inputs, outputs, equipment/resources (with what), personnel competence (with whom), procedures/methods (how), and performance indicators (what results).
| Process Aspect (Turtle Node) | Audit Checklist Question Prompt | ISO 9001:2015 Clause Reference |
|---|---|---|
| Inputs | What are the inputs to this process, and how are their requirements defined and verified? | Clause 8.1 (Operational planning and control) |
| Outputs | What are the final outputs of this process? How are they validated before release? | Clause 8.5.1 / 8.6 (Control & release) |
| Resources (With What) | What infrastructure, equipment, and software are used? How are they maintained? | Clause 7.1.3 / 7.1.5 (Infrastructure & monitoring) |
| Personnel (With Whom) | Who runs the process? How is their competence determined and recorded? | Clause 7.2 (Competence) |
| Methods (How) | What operating procedures, work instructions, or standards govern this process? | Clause 7.5 (Documented information) |
| Performance (Metrics) | What are the key performance indicators (KPIs) for this process? Are they monitored? | Clause 9.1.3 (Analysis and evaluation) |
Worked Scenario: Auditing a Software Firm Using Agile Sprints
An audit team is preparing to audit a software development firm certified under ISO 9001:2015. The firm uses Agile development methodologies, organizing its design and development (Clause 8.3) into two-week "sprints."
A novice auditor on the team proposes a clause-by-clause checklist, searching for traditional design phases like "design input documentation," "formal review meeting minutes," and "design sign-off certificates." The lead auditor rejects this approach because Agile software development does not produce traditional waterfall documentation.
Instead, the lead auditor helps the auditor design a process-based checklist that maps Agile ceremonies to ISO 9001:2015 requirements:
- Product Backlog Grooming is audited as Design Inputs (Clause 8.3.3).
- Sprint Planning Meetings is audited as Design Planning (Clause 8.3.2).
- Daily Stand-ups and Sprint Demos are audited as Design Review and Verification (Clause 8.3.4).
- Retrospectives are audited as Improvement and corrective actions (Clause 10.2).
By aligning the checklist with the client's Agile terminology, the auditor can gather objective evidence (sprint planning boards, JIRA tickets, and demo logs) that demonstrates QMS conformity without forcing the client to create redundant paper records.
Under ISO 19011:2018 Clause 6.3.2, who has the primary responsibility for preparing the audit plan, and how must it be treated prior to the onsite audit?
What is a primary risk associated with an auditor following an audit checklist too rigidly during a Stage 2 compliance audit?
When designing a process-based checklist for an organization's purchasing process, which node of the Turtle Diagram would prompt the auditor to inspect calibration records for testing equipment used in receiving inspection?