Section 4.1: Initiating the Audit and Feasibility Assessment
Key Takeaways
- Initiating an audit under ISO 19011:2018 Clause 6.2 involves establishing formal contact with the auditee's management.
- Feasibility must be determined by the lead auditor based on availability of information, cooperation, and adequate resources.
- Audit objectives establish the purpose, the scope defines boundaries, and the criteria represent the standards of comparison.
- Audit teams must collectively possess the competence required, with technical experts providing domain support but not auditing.
- Impartiality is paramount; auditors must not audit their own work or processes they have consulted on within the past two years.
Initiating the Audit and Feasibility Assessment
Initiating an audit marks the official commencement of the auditing process under ISO 19011:2018 guidelines. This initial phase sets the groundwork for the entire audit engagement, ensuring that the audit has a clear direction, the necessary permissions are secured, and the audit is realistic and achievable given the available resources. In certification audits governed by ISO/IEC 17021-1, this phase is formal and systematic, involving coordination between the certification body, the lead auditor, and the client organization.
Establishing Initial Contact with the Auditee
The audit team leader (lead auditor) is responsible for establishing formal contact with the auditee. This initial interaction is critical for building rapport, clarifying expectations, and ensuring a cooperative audit environment. The objectives of this contact include:
- Confirming the channels of communication and identifying authorized representatives (such as the Quality Manager).
- Confirming the authority to conduct the audit and verifying the audit objectives, scope, and criteria.
- Requesting access to relevant documents, records, and information necessary for planning, including information on risks and opportunities identified by the organization.
- Determining applicable statutory, regulatory, and contractual requirements relevant to the client's operations.
- Confirming the agreement on the involvement of observers, guides, and technical experts.
- Resolving logistics, safety requirements, security clearances, and scheduling for opening and closing meetings.
Under ISO/IEC 17021-1, certification bodies must have a formal process for determining audit time, which includes consideration of site count, complexity, technology, and outsourcing. During the initiation phase, the lead auditor must verify that the parameters used by the certification body to calculate the audit duration (often expressed in auditor-days) remain accurate. If the organization has added a new shift, opened a new warehouse, or outsourced a major process since the initial contract was signed, the lead auditor must recalculate feasibility. Proceeding with insufficient auditor-days violates ISO/IEC 17021-1 requirements and risks a non-conforming audit process.
Determining Audit Feasibility (ISO 19011 Clause 6.2.2)
Before proceeding with detailed planning, the lead auditor must determine if the audit is feasible. Feasibility is not assumed; it is a deliberate assessment. If the audit lacks feasibility, it will result in wasted resources, inaccurate findings, and an invalid audit report. Under ISO 19011:2018 Clause 6.2.2, the determination of feasibility must be based on the availability of the following:
- Sufficient and appropriate information for planning the audit (such as documented information of the QMS, process descriptions, and previous audit reports).
- Adequate cooperation from the auditee, ensuring that key personnel will be available for interviews and that the audit team will have access to physical and electronic sites.
- Adequate time and resources to conduct the audit. This includes travel time, the number of auditors relative to the size of the organization, and technological resources (such as for remote audits).
If the audit is deemed not feasible, the lead auditor must immediately notify the audit client (the party requesting the audit, which could be the certification body or internal management). The lead auditor should propose alternatives in consultation with the auditee, such as adjusting the audit scope, rescheduling the audit, or modifying the audit team composition.
| Feasibility Factor | Audit Risk if Not Met | Lead Auditor Action / Mitigation |
|---|---|---|
| Information Availability | Inability to prepare audit plans or checklists; blind auditing. | Postpone the audit or request immediate documentation submission. |
| Auditee Cooperation | Blocked access to key areas, defensive interviews, missing evidence. | Escalate to the audit client; clarify mutual benefits of the audit. |
| Resource Sufficiency | Rushed audits, skipped processes, inadequate sampling size. | Request extension of audit days or add another competent auditor. |
| Safety and Security | Physical harm to auditors; legal violations due to lack of clearance. | Obtain security clearance in advance; request safety training or PPE. |
Defining Audit Objectives, Scope, and Criteria
A critical step in initiating the audit is formalizing the audit objectives, scope, and criteria. These parameters must be established before any auditing activity begins.
- Audit Objectives: These define what the audit is intended to accomplish. In an ISO 9001 lead audit, typical objectives include determining the conformity of the QMS to the ISO 9001:2015 standard, evaluating the effectiveness of the QMS in achieving its intended outcomes, assessing the QMS's ability to satisfy customer and regulatory requirements, and identifying potential areas for improvement (Opportunities for Improvement - OFIs).
- Audit Scope: This defines the boundary and physical/organizational limits of the audit. It includes the physical locations, organizational units, processes, activities, and the specific timeframe covered by the audit. For example: "The quality management system governing the design, manufacture, and distribution of medical devices at the Austin, TX facility, covering operations from July 2025 to July 2026."
- Audit Criteria: These are the reference points against which audit evidence is compared. For an ISO 9001 audit, the criteria always include the ISO 9001:2015 standard itself, the organization’s own documented policies and procedures, applicable statutory and regulatory requirements, and customer contracts.
Exam Tip: The scope defines where and what we audit; the criteria defines what standard we compare it to. Confusion between these terms is a common source of exam errors.
Selecting the Audit Team and Defining Roles
The composition of the audit team must ensure collective competence to achieve the audit objectives. The lead auditor must define the roles and responsibilities within the team. During team selection, the lead auditor must also evaluate potential conflicts of interest. Under the ethical principles of ISO 19011 and ISO/IEC 17021-1, an auditor must not audit their own work or any system they have consulted on within the past two years. If a selected auditor has provided consultancy services to the client recently, the lead auditor must replace them immediately to maintain impartiality.
- Audit Team Leader (Lead Auditor): Coordinates all activities, drafts the audit plan, assigns tasks to team members, manages conflicts, leads the opening and closing meetings, and compiles the final audit report.
- Auditors: Conduct interviews, review documents, observe operations, gather evidence, and document findings under the direction of the lead auditor.
- Technical Experts: Provide specialized knowledge (such as chemistry or software engineering) but do not act as independent auditors. They must be accompanied by an auditor and cannot make audit conclusions or write nonconformities independently.
- Observers and Guides: Observers (such as consultants, trainee auditors, or regulators) accompany the team but must not influence or interfere with the audit. Guides (appointed by the auditee) assist with navigation, ensure safety compliance, and witness the audit on behalf of the auditee.
Worked Scenario: Evaluating Feasibility in a Restricted Environment
Consider a lead auditor assigned to conduct a recertification audit for a defense contractor manufacturing aerospace components. During the initial contact, the client reveals that two main production lines are under high-security military restrictions, and audit team members without top-secret clearance cannot enter. The audit team currently has no cleared members.
The lead auditor must assess the feasibility of the audit. Because these two restricted production lines constitute 60% of the QMS scope, auditing only the unrestricted areas would yield insufficient evidence to determine QMS conformity. The lead auditor determines that the audit is currently not feasible due to lack of access (information and cooperation).
Rather than cancelling, the lead auditor contacts the certification body and proposes an alternative: either sub-contracting an auditor who already holds the required security clearance or requesting the client to arrange temporary escort clearances and visual-redaction protocols. This ensures the audit can be completed without compromising security or audit integrity.
During the initiation phase of an ISO 9001 certification audit, the lead auditor discovers that the client has recently outsourced their entire calibration process, which was previously performed in-house. What should the lead auditor do first to ensure feasibility?
According to ISO 19011:2018, which of the following is a primary criterion for determining the feasibility of an audit during the initiation phase?
An audit team includes a technical expert who is a specialist in aerospace metallurgical testing. During the audit, the technical expert notices a potential deviation in heat-treatment records. How must the technical expert handle this finding?