The audit process is structured in eight stages, and the sequence is deliberate. Each stage produces a defined output that the next stage depends on. Planning without preparation produces an audit that misses the site's actual risk profile. Fieldwork without a disciplined evidence stage produces findings that cannot be substantiated later. Findings without corrective action and verification produce a report that changes nothing.
The structure exists to make the audit reproducible. Another competent auditor, given the same evidence, should reach the same conclusion. That is the standard ISO 19011:2018 sets for audit conduct, and it is the standard a finding has to meet if it is going to withstand challenge from a site manager, a customer, or a certification body.
| Step | Activity | Output |
|---|---|---|
| 01 Plan | Define audit scope, objectives and criteria. Agree dates, areas, processes and the standards the audit will be conducted against. Identify the site's risk profile and allocate audit time accordingly. | Audit plan with documented scope, objectives, criteria and schedule |
| 02 Prepare | Review the documented system, previous audit reports, open corrective actions, complaint and nonconformance trends. Build the audit checklist against the agreed criteria. | Prepared checklist, document review notes, focus areas identified |
| 03 Audit | Conduct the on-site or remote assessment. Observe practice under normal operating conditions, interview personnel at the point of work, and test controls rather than only reviewing their description. | Completed checklist with observations recorded against each requirement |
| 04 Evidence | Capture objective evidence for every observation — records, measurements, photographs, documented statements. Attach evidence to the observation at the point of capture, not afterwards. | Evidence pack linked to each observation, timestamped and traceable |
| 05 Findings | Classify each nonconformity by severity and against the specific requirement it fails. Distinguish systemic weakness from isolated lapse. Write findings in plain, actionable language. | Classified findings register with requirement references and evidence links |
| 06 Corrective Action | Issue corrective action requirements. Require root cause analysis, not symptom correction. Agree responsibility, due date, and the evidence that will demonstrate effectiveness. | Corrective action requests with defined verification criteria and due dates |
| 07 Verify | Confirm that corrective actions have been implemented, that the stated root cause is supported, and that the control is effective at a suitable interval after implementation. | Verification record per corrective action — closed or not closed, with reasons |
| 08 Report | Deliver the structured audit report: scope, criteria, findings with evidence, corrective action status, risk-based observations, and clear priorities. | Final audit report with complete evidence chain and prioritised actions |