Exemplar Global Certified Courses from USD 99. Ending Soon!

Audit Process Steps: From Planning to Follow Up

AW

Team @ Audit Workshop

12 min read
Audit Process Steps: From Planning to Follow Up

Understanding the audit process steps from planning through to follow up is one of the most practical things any auditor or quality manager can invest time in. Whether you are preparing to conduct your first internal audit or you want to sharpen your approach before a certification audit, knowing exactly what happens at each stage, and why it matters, makes the difference between an audit that drives real improvement and one that ticks boxes and collects dust.

This article walks through every major stage of the audit process in the sequence a competent auditor would follow it. Each step builds on the one before. Skip one, and the whole thing gets shaky.

Why the Audit Process Exists as a Structured Sequence

Auditing is not just showing up and asking questions. It is a disciplined process governed by ISO 19011, the international guidelines for auditing management systems. The structure exists because audits need to be repeatable, objective, and evidence based. Without a consistent process, two auditors looking at the same system could reach completely different conclusions, and neither could justify their findings with confidence.

The audit process also protects the auditee. When auditors follow a defined sequence, the organisation being audited knows what to expect, has the opportunity to prepare, and can trust that findings are grounded in evidence rather than opinion.

Step 1: Initiating the Audit

Every audit starts with initiation, which means establishing that the audit should happen, who is responsible for it, and what it is trying to achieve. For internal audits, this typically involves the audit programme manager or quality manager assigning an auditor and confirming the scope and objectives.

At this stage, you confirm:

  • The purpose of the audit (conformity check, surveillance, improvement focus, or a combination)
  • The scope, meaning which processes, areas, or clauses will be covered
  • The criteria, meaning what the audit will be measured against (the standard, procedures, legal requirements)
  • Who will conduct the audit, and whether they are independent of the area being audited

Auditor independence is non negotiable. An auditor cannot objectively assess their own work. If you are the quality manager for a process, you should not be auditing that process yourself. This is not just good practice, it is a requirement under ISO 9001 Clause 9.2 and reinforced in ISO 19011.

For a deeper look at how to write clear audit objectives at this stage, see our article on how to write audit objectives that actually focus your audit.

Step 2: Preparing the Audit Plan

Once the audit has been initiated, the lead auditor or assigned auditor prepares the audit plan. This is a working document that outlines the logistics and sequence of the audit. It is not a checklist. It is a schedule that tells everyone involved where they need to be and when.

A solid audit plan includes:

  • The audit objectives, scope, and criteria
  • The date and location of the audit
  • The processes and areas to be audited
  • The time allocated to each area
  • The names of the auditors and their assigned areas
  • The name of the audit team leader
  • The timing of the opening and closing meetings

The plan should be sent to the auditee organisation in advance. This is not about giving them time to hide problems. It is about ensuring the right people are available, records are accessible, and the audit runs efficiently. Surprises waste time and create unnecessary tension.

For internal audits, the plan does not need to be elaborate. A one page document with clear timings is often sufficient. For certification or supplier audits, the plan tends to be more detailed, particularly if multiple sites or teams are involved.

Step 3: Preparing the Audit Checklist and Reviewing Documents

Before arriving on site, the auditor should review relevant documentation. This is sometimes called a document review or desktop review. The goal is to understand how the organisation says it operates so you can compare that with what you actually find during the audit.

Documents to review typically include:

  • The management system manual or documented scope
  • Relevant procedures and work instructions
  • Previous audit reports and corrective actions
  • Risk registers and objectives
  • Any legal or regulatory requirements relevant to the scope

From this review, you build your audit checklist. A checklist is a prompt, not a script. It keeps you on track and ensures you cover the required areas, but it should not stop you from following an interesting thread when the evidence leads somewhere unexpected.

The most common mistake new auditors make here is building a checklist that mirrors the standard clause by clause and then working through it mechanically. A process based approach, where you follow the flow of work rather than the numbering of the standard, almost always produces better findings.

Step 4: Conducting the Opening Meeting

The opening meeting marks the formal start of the on site audit. It is a short, structured meeting with the auditee organisation that sets expectations for the day.

In the opening meeting, the lead auditor typically covers:

  • Introductions of the audit team and any observers
  • Confirmation of the audit scope, objectives, and criteria
  • The audit schedule and logistics (where you will be, who you need to speak with)
  • How findings will be recorded and communicated
  • Confirmation that the audit is confidential
  • An invitation for the auditee to ask questions

Keep it professional but not stiff. The opening meeting sets the tone for the whole day. If you come across as adversarial or bureaucratic, people will be guarded for the rest of the audit. If you are clear, calm, and respectful, people tend to be more open.

For a practical guide to running this meeting well, see our article on how to conduct an opening meeting for an ISO audit.

Step 5: Gathering Audit Evidence

This is the core of the audit. Gathering evidence involves three main methods: interviewing people, reviewing documents and records, and direct observation of activities and conditions.

Each method checks the others. If a procedure says staff are trained to a certain standard, you interview a staff member to see if they understand it, review training records to confirm it was done, and observe the activity to see if the training is reflected in practice. When all three point in the same direction, you have solid evidence. When they contradict each other, you have found something worth investigating further.

Interviewing

Interviews are where most of your evidence comes from. Ask open questions that require explanation rather than yes or no answers. Give people time to respond. Listen carefully. Follow up on anything that seems inconsistent or incomplete. Avoid leading questions that suggest the answer you are looking for.

Document and Record Review

Check that documented information exists where the standard or procedure requires it, that it is current, and that it reflects actual practice. Look for version numbers, approval signatures, review dates, and evidence that records are being completed in real time rather than retrospectively.

Observation

Walk the floor. Watch how work is actually done. Compare what you see with what the procedures describe. Note conditions, behaviours, and physical evidence. Observation catches things that interviews and documents miss entirely.

Take clear, factual notes throughout. Record what you saw, heard, or read, not your interpretation of it. Your notes are the foundation for every finding you write later.

Step 6: Generating Audit Findings

As you gather evidence, you will begin forming findings. Findings fall into several categories:

  • Conformity: The evidence shows the requirement is being met.
  • Nonconformity: The evidence shows a requirement is not being met. This can be major (significant failure or absence of a system element) or minor (isolated lapse that does not indicate a systemic breakdown).
  • Observation or Opportunity for Improvement: Something that is not a nonconformity but warrants attention.

Every nonconformity must be supported by objective evidence. You cannot raise a finding based on a feeling or a suspicion. The finding must state the requirement, describe the evidence of non fulfilment, and reference the specific clause or document that has not been met.

Vague findings like “training records are not adequate” are not useful. A well written nonconformity reads more like: “Three of five operators interviewed in the welding bay could not demonstrate awareness of the relevant work instruction (WI 04.2). Training records for two of these operators were last updated in 2022, contrary to the requirement in Procedure P 07.2 that competence be reviewed annually.”

That finding is specific, evidence based, and actionable.

Step 7: Conducting the Closing Meeting

The closing meeting is where you formally present your findings to the auditee organisation. It mirrors the opening meeting in structure but focuses on outcomes rather than logistics.

In the closing meeting, the lead auditor:

  • Thanks the auditee for their cooperation
  • Summarises the audit scope and what was covered
  • Presents the findings, including any nonconformities and observations
  • Confirms the audit conclusion (for certification audits, this includes a recommendation)
  • Explains the next steps, particularly around corrective actions and timelines
  • Invites questions and clarification

Do not surprise people at the closing meeting with findings they have not heard before. Good auditors communicate significant issues as they find them, so the closing meeting is a summary, not a revelation. Surprises at this stage erode trust and often lead to disputes about findings.

Step 8: Preparing and Distributing the Audit Report

After the audit, the lead auditor prepares the formal audit report. The report is the permanent record of what was audited, how it was conducted, what was found, and what conclusions were reached.

A complete audit report typically includes:

  • Audit objectives, scope, and criteria
  • Audit team members and auditee representatives
  • Dates and locations
  • A summary of the audit process
  • All findings, with supporting evidence
  • The audit conclusion
  • Any significant issues or areas of concern
  • Opportunities for improvement noted during the audit

The report should be factual, clear, and free of ambiguity. Avoid language that editorialises or attributes blame. The report goes to the audit client, which may be the organisation's own management or a certification body, depending on the type of audit.

Timeliness matters. A report delivered six weeks after the audit has lost much of its value. Aim to have the report finalised and distributed within a week of the audit wherever possible.

Step 9: Corrective Action and Follow Up

Raising a nonconformity is not the end of the process. The auditee is required to investigate the root cause of each nonconformity, determine appropriate corrective actions, implement those actions, and provide evidence of effectiveness.

As the auditor, your role in follow up is to verify that the corrective actions have actually addressed the root cause, not just the symptom. This is where many organisations fall short. They fix the specific instance that was found but do not address the underlying reason it happened, so the same problem reappears at the next audit.

Follow up can happen in several ways:

  • Review of submitted evidence (documents, records, photos) without a site visit
  • A dedicated follow up audit visit to verify implementation
  • Verification at the next scheduled audit

For certification audits, major nonconformities typically require evidence of corrective action within a defined timeframe before the certificate can be issued or maintained. Minor nonconformities may be verified at the next surveillance audit.

For internal audits, the quality manager or audit programme manager is responsible for tracking corrective actions through to closure. An action that is raised but never verified as effective is not a closed finding. It is an outstanding risk.

For a practical guide to managing this process, see our article on managing corrective actions after an ISO audit.

Putting It All Together: The Audit as a Continuous Loop

One thing experienced auditors understand is that the audit process is not a one off event. It is part of a continuous improvement cycle. The findings from one audit inform the planning of the next. Patterns in nonconformities point to systemic issues that deserve deeper investigation. Corrective actions that prove effective become inputs to process improvement.

This is why the audit programme, rather than individual audits, is the real tool for improvement. A single audit gives you a snapshot. A well managed programme gives you a trend line, and trend lines tell you where the system is genuinely improving and where it is stagnating.

If you are building or managing an internal audit programme, the discipline of following these steps consistently, audit after audit, is what builds credibility with management and with certification bodies. Audits that skip steps, rush the planning, or skip the follow up produce findings that nobody acts on. Audits that follow the full process produce findings that change things.

Building Your Audit Skills Through Formal Training

Understanding these steps conceptually is one thing. Applying them under real conditions, with real auditees, real time pressure, and real evidence to evaluate, is another. That is where structured auditor training makes a meaningful difference.

At Audit Workshop, our internal auditor and lead auditor courses are built around practical application of the audit process. You do not just learn the theory. You practise planning an audit, conducting interviews, writing nonconformities, and running opening and closing meetings, all in a structured learning environment with feedback from an experienced practitioner.

Whether you are starting out with an internal auditor course for ISO 9001, ISO 14001, or ISO 45001, or you are ready to progress to lead auditor level, the training is designed to give you the skills and confidence to conduct audits that actually stand up. Visit auditworkshop.com to explore current course options and enrolment dates.

Frequently Asked Questions

The main steps are: initiating the audit, preparing the audit plan, reviewing documents and building a checklist, conducting the opening meeting, gathering evidence through interviews, document review and observation, generating findings, conducting the closing meeting, preparing and distributing the audit report, and following up on corrective actions. Each step feeds into the next, and skipping any one of them weakens the overall audit.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor Training Course
  • Lead Auditor
  • Self-Paced Online
  • Exemplar Global
  • USD 199USD 789
ISO 45001:2018 Lead Auditor Training Course
  • Lead Auditor
  • Self-Paced Online
  • Exemplar Global
  • USD 199USD 789
ISO 14001:2026 Lead Auditor Training Course
  • Lead Auditor
  • Self-Paced Online
  • Exemplar Global
  • USD 199USD 789
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.