Understanding the audit process steps from planning through to follow up is one of the most practical things any auditor or quality manager can invest time in. Whether you are preparing to conduct your first internal audit or you want to sharpen your approach before a certification audit, knowing exactly what happens at each stage, and why it matters, makes the difference between an audit that drives real improvement and one that ticks boxes and collects dust.
On this page
This article walks through every major stage of the audit process in the sequence a competent auditor would follow it. Each step builds on the one before. Skip one, and the whole thing gets shaky.
Why the Audit Process Exists as a Structured Sequence
Auditing is not just showing up and asking questions. It is a disciplined process governed by ISO 19011, the international guidelines for auditing management systems. The structure exists because audits need to be repeatable, objective, and evidence based. Without a consistent process, two auditors looking at the same system could reach completely different conclusions, and neither could justify their findings with confidence.
The audit process also protects the auditee. When auditors follow a defined sequence, the organisation being audited knows what to expect, has the opportunity to prepare, and can trust that findings are grounded in evidence rather than opinion.
Exemplar Global Recognised Training ProviderRTP No. 310970Step 1: Initiating the Audit
Every audit starts with initiation, which means establishing that the audit should happen, who is responsible for it, and what it is trying to achieve. For internal audits, this typically involves the audit programme manager or quality manager assigning an auditor and confirming the scope and objectives.
At this stage, you confirm:
- The purpose of the audit (conformity check, surveillance, improvement focus, or a combination)
- The scope, meaning which processes, areas, or clauses will be covered
- The criteria, meaning what the audit will be measured against (the standard, procedures, legal requirements)
- Who will conduct the audit, and whether they are independent of the area being audited
Auditor independence is non negotiable. An auditor cannot objectively assess their own work. If you are the quality manager for a process, you should not be auditing that process yourself. This is not just good practice, it is a requirement under ISO 9001 Clause 9.2 and reinforced in ISO 19011.
For a deeper look at how to write clear audit objectives at this stage, see our article on how to write audit objectives that actually focus your audit.
Step 2: Preparing the Audit Plan
Once the audit has been initiated, the lead auditor or assigned auditor prepares the audit plan. This is a working document that outlines the logistics and sequence of the audit. It is not a checklist. It is a schedule that tells everyone involved where they need to be and when.
A solid audit plan includes:
- The audit objectives, scope, and criteria
- The date and location of the audit
- The processes and areas to be audited
- The time allocated to each area
- The names of the auditors and their assigned areas
- The name of the audit team leader
- The timing of the opening and closing meetings
The plan should be sent to the auditee organisation in advance. This is not about giving them time to hide problems. It is about ensuring the right people are available, records are accessible, and the audit runs efficiently. Surprises waste time and create unnecessary tension.
For internal audits, the plan does not need to be elaborate. A one page document with clear timings is often sufficient. For certification or supplier audits, the plan tends to be more detailed, particularly if multiple sites or teams are involved.
Step 3: Preparing the Audit Checklist and Reviewing Documents
Before arriving on site, the auditor should review relevant documentation. This is sometimes called a document review or desktop review. The goal is to understand how the organisation says it operates so you can compare that with what you actually find during the audit.
Documents to review typically include:
- The management system manual or documented scope
- Relevant procedures and work instructions
- Previous audit reports and corrective actions
- Risk registers and objectives
- Any legal or regulatory requirements relevant to the scope
From this review, you build your audit checklist. A checklist is a prompt, not a script. It keeps you on track and ensures you cover the required areas, but it should not stop you from following an interesting thread when the evidence leads somewhere unexpected.
The most common mistake new auditors make here is building a checklist that mirrors the standard clause by clause and then working through it mechanically. A process based approach, where you follow the flow of work rather than the numbering of the standard, almost always produces better findings.
Step 4: Conducting the Opening Meeting
The opening meeting marks the formal start of the on site audit. It is a short, structured meeting with the auditee organisation that sets expectations for the day.
In the opening meeting, the lead auditor typically covers:
- Introductions of the audit team and any observers
- Confirmation of the audit scope, objectives, and criteria
- The audit schedule and logistics (where you will be, who you need to speak with)
- How findings will be recorded and communicated
- Confirmation that the audit is confidential
- An invitation for the auditee to ask questions
Keep it professional but not stiff. The opening meeting sets the tone for the whole day. If you come across as adversarial or bureaucratic, people will be guarded for the rest of the audit. If you are clear, calm, and respectful, people tend to be more open.
For a practical guide to running this meeting well, see our article on how to conduct an opening meeting for an ISO audit.
Step 5: Gathering Audit Evidence
This is the core of the audit. Gathering evidence involves three main methods: interviewing people, reviewing documents and records, and direct observation of activities and conditions.
Each method checks the others. If a procedure says staff are trained to a certain standard, you interview a staff member to see if they understand it, review training records to confirm it was done, and observe the activity to see if the training is reflected in practice. When all three point in the same direction, you have solid evidence. When they contradict each other, you have found something worth investigating further.
Interviewing
Interviews are where most of your evidence comes from. Ask open questions that require explanation rather than yes or no answers. Give people time to respond. Listen carefully. Follow up on anything that seems inconsistent or incomplete. Avoid leading questions that suggest the answer you are looking for.
Document and Record Review
Check that documented information exists where the standard or procedure requires it, that it is current, and that it reflects actual practice. Look for version numbers, approval signatures, review dates, and evidence that records are being completed in real time rather than retrospectively.
Observation
Walk the floor. Watch how work is actually done. Compare what you see with what the procedures describe. Note conditions, behaviours, and physical evidence. Observation catches things that interviews and documents miss entirely.
Take clear, factual notes throughout. Record what you saw, heard, or read, not your interpretation of it. Your notes are the foundation for every finding you write later.
Step 6: Generating Audit Findings
As you gather evidence, you will begin forming findings. Findings fall into several categories:
- Conformity: The evidence shows the requirement is being met.
- Nonconformity: The evidence shows a requirement is not being met. This can be major (significant failure or absence of a system element) or minor (isolated lapse that does not indicate a systemic breakdown).
- Observation or Opportunity for Improvement: Something that is not a nonconformity but warrants attention.
Every nonconformity must be supported by objective evidence. You cannot raise a finding based on a feeling or a suspicion. The finding must state the requirement, describe the evidence of non fulfilment, and reference the specific clause or document that has not been met.
Vague findings like “training records are not adequate” are not useful. A well written nonconformity reads more like: “Three of five operators interviewed in the welding bay could not demonstrate awareness of the relevant work instruction (WI 04.2). Training records for two of these operators were last updated in 2022, contrary to the requirement in Procedure P 07.2 that competence be reviewed annually.”
That finding is specific, evidence based, and actionable.
Step 7: Conducting the Closing Meeting
The closing meeting is where you formally present your findings to the auditee organisation. It mirrors the opening meeting in structure but focuses on outcomes rather than logistics.
In the closing meeting, the lead auditor:
- Thanks the auditee for their cooperation
- Summarises the audit scope and what was covered
- Presents the findings, including any nonconformities and observations
- Confirms the audit conclusion (for certification audits, this includes a recommendation)
- Explains the next steps, particularly around corrective actions and timelines
- Invites questions and clarification
Do not surprise people at the closing meeting with findings they have not heard before. Good auditors communicate significant issues as they find them, so the closing meeting is a summary, not a revelation. Surprises at this stage erode trust and often lead to disputes about findings.
Step 8: Preparing and Distributing the Audit Report
After the audit, the lead auditor prepares the formal audit report. The report is the permanent record of what was audited, how it was conducted, what was found, and what conclusions were reached.
A complete audit report typically includes:
- Audit objectives, scope, and criteria
- Audit team members and auditee representatives
- Dates and locations
- A summary of the audit process
- All findings, with supporting evidence
- The audit conclusion
- Any significant issues or areas of concern
- Opportunities for improvement noted during the audit
The report should be factual, clear, and free of ambiguity. Avoid language that editorialises or attributes blame. The report goes to the audit client, which may be the organisation's own management or a certification body, depending on the type of audit.
Timeliness matters. A report delivered six weeks after the audit has lost much of its value. Aim to have the report finalised and distributed within a week of the audit wherever possible.
Step 9: Corrective Action and Follow Up
Raising a nonconformity is not the end of the process. The auditee is required to investigate the root cause of each nonconformity, determine appropriate corrective actions, implement those actions, and provide evidence of effectiveness.
As the auditor, your role in follow up is to verify that the corrective actions have actually addressed the root cause, not just the symptom. This is where many organisations fall short. They fix the specific instance that was found but do not address the underlying reason it happened, so the same problem reappears at the next audit.
Follow up can happen in several ways:
- Review of submitted evidence (documents, records, photos) without a site visit
- A dedicated follow up audit visit to verify implementation
- Verification at the next scheduled audit
For certification audits, major nonconformities typically require evidence of corrective action within a defined timeframe before the certificate can be issued or maintained. Minor nonconformities may be verified at the next surveillance audit.
For internal audits, the quality manager or audit programme manager is responsible for tracking corrective actions through to closure. An action that is raised but never verified as effective is not a closed finding. It is an outstanding risk.
For a practical guide to managing this process, see our article on managing corrective actions after an ISO audit.
Exemplar Global Recognised Training ProviderRTP No. 310970Putting It All Together: The Audit as a Continuous Loop
One thing experienced auditors understand is that the audit process is not a one off event. It is part of a continuous improvement cycle. The findings from one audit inform the planning of the next. Patterns in nonconformities point to systemic issues that deserve deeper investigation. Corrective actions that prove effective become inputs to process improvement.
This is why the audit programme, rather than individual audits, is the real tool for improvement. A single audit gives you a snapshot. A well managed programme gives you a trend line, and trend lines tell you where the system is genuinely improving and where it is stagnating.
If you are building or managing an internal audit programme, the discipline of following these steps consistently, audit after audit, is what builds credibility with management and with certification bodies. Audits that skip steps, rush the planning, or skip the follow up produce findings that nobody acts on. Audits that follow the full process produce findings that change things.
Building Your Audit Skills Through Formal Training
Understanding these steps conceptually is one thing. Applying them under real conditions, with real auditees, real time pressure, and real evidence to evaluate, is another. That is where structured auditor training makes a meaningful difference.
At Audit Workshop, our internal auditor and lead auditor courses are built around practical application of the audit process. You do not just learn the theory. You practise planning an audit, conducting interviews, writing nonconformities, and running opening and closing meetings, all in a structured learning environment with feedback from an experienced practitioner.
Whether you are starting out with an internal auditor course for ISO 9001, ISO 14001, or ISO 45001, or you are ready to progress to lead auditor level, the training is designed to give you the skills and confidence to conduct audits that actually stand up. Visit auditworkshop.com to explore current course options and enrolment dates.













