Section 6.3: Preparing, Approving, and Distributing the Audit Report

Key Takeaways

  • The Lead Auditor has ultimate responsibility for the preparation, content, and accuracy of the audit report.
  • The audit report must include key metadata, audit objectives, scope, findings, conclusions, and confidentiality statements.
  • The audit report must be completed and distributed within the agreed timeframes established in the audit plan.
  • Ownership of the audit report remains with the audit client, and its contents must be kept strictly confidential.
  • Audit records, including notes and drafts, must be retained or disposed of securely in accordance with regulatory and CB procedures.
Last updated: July 2026

Section 6.3: Preparing, Approving, and Distributing the Audit Report

The audit report is the official record of the audit. It is the primary vehicle for communicating the audit conclusions to the audit client, the auditee's management, and, in third-party audits, the certification body's decision-making committee. Under ISO 19011:2018 Clause 6.5, the Lead Auditor is fully responsible for the preparation, accuracy, and distribution of this report. The report must provide a complete, fair, and clear record of the audit, enabling the reader to understand the current state of the organization's Quality Management System (QMS).

Mandatory Contents of the Audit Report

An ISO 9001:2015 audit report must not be a disorganized collection of findings. It must follow a structured format. According to ISO 19011:2018, the audit report must contain (or refer to) the following elements:

  1. Audit Objectives: What the audit was designed to achieve (e.g., verifying compliance with ISO 9001:2015, assessing readiness for a scope expansion, or evaluating supplier capability).
  2. Audit Scope: The physical boundaries, organizational units, and processes audited (e.g., "Design, manufacturing, and distribution of medical devices at the Austin, TX facility").
  3. Audit Client: The organization or individual who commissioned the audit.
  4. Auditee Representation: Identification of the organization audited and key personnel involved.
  5. Audit Team Details: The names of the Lead Auditor, team auditors, technical experts, and observers.
  6. Dates and Locations: The exact dates when the audit was conducted and the physical sites visited (including remote auditing details if applicable).
  7. Audit Criteria: The standards, procedures, and regulatory requirements against which the QMS was evaluated (e.g., ISO 9001:2015, internal procedure Manual-QMS-01, and federal safety regulations).
  8. Audit Findings and Evidence: A summary of the findings, including references to conforming areas, and detailed documentation of all major and minor nonconformities and Opportunities for Improvement (OFIs).
  9. Audit Conclusions: The audit team's assessment of the overall effectiveness of the QMS, the level of system maturity, management's commitment to the quality policy, and whether the quality objectives are being met.
  10. Certification Recommendation: For registration/certification audits, a clear statement of recommendation (e.g., recommendation for certification, recommendation pending successful corrective actions, or non-recommendation).
  11. Confidentiality Statement: A formal statement confirming that the report's contents are confidential and will not be disclosed to third parties without the auditee's express permission.
  12. Distribution List: A list of the specific individuals authorized to receive the report.

Timelines, Approval, and Distribution

The timeline for issuing the audit report is typically defined in the initial audit plan or contract. In third-party certification audits, certification bodies often establish strict rules (e.g., the report must be submitted to the CB and the auditee within 10 to 15 business days after the closing meeting).

Approval Process

Before distribution, the audit report must be reviewed and approved.

  • In first-party (internal) audits, the Lead Auditor approves the report.
  • In second-party (supplier) audits, the Lead Auditor and the purchasing/quality manager of the client organization approve it.
  • In third-party (certification) audits, the Lead Auditor signs off on the report, but it is then submitted to the Certification Body's technical review committee. Under ISO/IEC 17021-1, the final decision to grant, maintain, or renew certification is made not by the auditor, but by an independent reviewer or committee within the CB who was not involved in the audit. This ensures impartiality.

Distribution and Ownership

The audit report is the property of the audit client (the party that commissioned and paid for the audit).

  • In a third-party registration audit, the client and the auditee are usually the same entity, so the report is distributed to the organization's senior management and the CB.
  • In a supplier audit, the report is submitted to the purchasing company (the client) and may be shared with the supplier (the auditee) at the client's discretion.
  • The Lead Auditor must distribute the report only to the parties listed on the approved distribution list. Disseminating the report or its findings to unauthorized personnel is a severe breach of professional ethics and confidentiality requirements.

Record Retention and Confidentiality

Under ISO 19011:2018 and ISO/IEC 17021-1, auditors and auditing organizations must establish procedures for the secure storage and disposal of audit records.

What Records are Retained?

The audit file typically includes:

  • The audit plan and audit programme.
  • Completed checklists and auditor notes (objective evidence records).
  • Signed attendance sheets from the opening and closing meetings.
  • The finalized audit report.
  • Documents related to nonconformities, corrective action plans, and verification records.

Retention Period and Disposal

Audit records must be retained for a specified period, which is often determined by regulatory requirements, accreditation body rules, or certification body policies (typically 3 to 6 years, covering at least one full certification cycle). Once the retention period expires, all documents—especially physical notes, drafts of the report, and proprietary drawings collected during the audit—must be securely destroyed. Digital files must be permanently deleted, and physical documents must be shredded. This protects the auditee's intellectual property and trade secrets, preventing unauthorized access to sensitive operational and financial information.

Test Your Knowledge

Who holds the ultimate responsibility for the preparation, accuracy, and contents of the final ISO 9001 audit report?

A
B
C
D
Test Your Knowledge

In third-party certification audits, who has the final authority to grant, maintain, or renew an organization's ISO 9001 certification?

A
B
C
D
Test Your Knowledge

To whom does the ownership of the final audit report belong, and how must its distribution be managed?

A
B
C
D