When auditors sit down to plan an audit, one of the most consequential decisions they make is how to structure their approach. Do you work through the standard clause by clause, ticking off requirements as you go? Or do you follow the organisation's actual processes from start to finish, letting the evidence guide you to the clauses? This is the core question behind process based vs clause based auditing, and the answer shapes everything from how you write your checklist to what findings you actually surface.
On this page
Both approaches have their place. Neither is inherently wrong. But understanding the difference, and knowing when to use each one, separates auditors who find real problems from those who produce tidy reports that miss the point entirely.
What Is Clause Based Auditing?
Clause based auditing is exactly what it sounds like. You take the standard, work through each numbered clause, and verify that the organisation has met each requirement. Clause 4.1 gets ticked. Clause 5.1 gets ticked. Clause 8.4 gets ticked. You move systematically through the structure until you have covered the whole standard.
This approach has genuine appeal, particularly for new auditors. The standard gives you a ready-made framework. You know what you need to cover. It is hard to forget a requirement when you are literally working down a numbered list. For internal auditors who are new to the role and still building confidence, clause based auditing provides a scaffold that keeps them on track.
There are also situations where clause based auditing is genuinely appropriate. When you are conducting a document review during a Stage 1 audit, working through clauses to check that documented information exists is a logical approach. When you are auditing a specific system element like documented information control or the internal audit programme, a clause-focused lens makes sense.
The Limitations of Clause Based Auditing
The problem with clause based auditing is that it mirrors how the standard is written, not how the organisation actually works. Real organisations do not operate by clause. They take orders, design products, purchase materials, manufacture goods, deliver services, handle complaints, and try to improve. None of that maps neatly onto a numbered list.
When you audit clause by clause, you risk finding conformance in isolation while missing nonconformity in practice. A company might have a documented procedure for supplier evaluation that satisfies Clause 8.4 on paper. But if you follow an actual purchase order through the system, you might find that nobody uses the approved supplier list, that the evaluation records are two years out of date, and that the purchasing manager has never seen the procedure. The clause gets ticked. The problem stays hidden.
Clause based auditing also tends to fragment the audit into disconnected conversations. You spend thirty minutes with the quality manager on Clause 7, then move to operations for Clause 8, then back to management for Clause 9. The connections between these areas, which is often where the real breakdowns occur, never get examined.
Exemplar Global Recognised Training ProviderRTP No. 310970What Is Process Based Auditing?
Process based auditing follows the way the organisation actually delivers its products or services. Instead of asking does this organisation have a procedure for X, you ask show me how X actually happens. You start at the beginning of a process, follow it through to the end, and gather evidence at each step.
This approach is directly aligned with the process approach that underpins all modern ISO management system standards. ISO 9001, ISO 14001, and ISO 45001 all require organisations to identify and manage their processes and their interactions. The process approach is not just a concept in the standard. It is the architecture the standard was built on. Auditing in a process based way respects that architecture.
In practice, process based auditing might look like this. You select the production process as your audit scope. You start at the point where a customer order is received. You follow the order through design, planning, procurement, production, inspection, and dispatch. At each stage, you ask what inputs are needed, what controls are in place, what outputs are produced, and how performance is monitored. Along the way, you naturally encounter requirements from multiple clauses of the standard, competence, documented information, operational controls, monitoring, nonconforming outputs, and customer communication, all in context.
Why the Process Approach Finds More
The reason process based auditing tends to surface more meaningful findings is that it tests the system as it actually functions, not as it was designed on paper. You are watching a live performance, not reading the script.
Consider a safety audit under ISO 45001. A clause based auditor might verify that the organisation has a hazard identification procedure (Clause 6.1.2.1), a risk assessment methodology (Clause 6.1.2.2), and documented controls (Clause 8.1). All boxes ticked. But a process based auditor who follows a maintenance work order from task assignment through to completion might find that the permit to work system is bypassed for routine jobs, that workers have not been told about a new chemical introduced three months ago, and that the hierarchy of controls has not been applied to a recently changed task. The clause based audit found conformance. The process based audit found the gaps that matter.
This is not a hypothetical. It reflects what experienced auditors see in the field. Systems that look compliant on paper often have significant gaps in practice, and those gaps only become visible when you follow the actual flow of work.
How ISO 9001 and the High Level Structure Support Process Based Auditing
The High Level Structure (HLS) that underpins ISO 9001, ISO 14001, and ISO 45001 was deliberately designed to support process based auditing. Clause 4.4 in each of these standards requires the organisation to determine its processes, their sequence and interaction, the inputs and outputs, the criteria and methods, the resources, the responsibilities, the risks, and the performance indicators. This is essentially a blueprint for process based auditing built directly into the standard.
When you audit a process, you are directly testing Clause 4.4 conformance. You are asking whether the organisation actually manages its processes the way the standard requires, with defined inputs and outputs, appropriate controls, competent people, monitored performance, and a mechanism for identifying and addressing problems.
Tools like turtle diagrams and SIPOC models are commonly used in process based auditing to structure your thinking. A turtle diagram maps a process by asking what goes in, what comes out, who does it, what equipment and materials are used, what methods and procedures apply, and what indicators measure performance. Turtle diagrams are particularly useful for planning process audits because they force you to think about the process holistically before you walk through the door.
Combining Both Approaches Effectively
The most effective auditors do not choose one approach and ignore the other. They use process based auditing as the primary method for gathering evidence, and clause based auditing as a cross-check to make sure nothing has been missed.
Here is how that works in practice. You plan your audit around three or four key processes. For each process, you develop a set of questions and evidence points that follow the flow of work. As you conduct the audit, you naturally cover requirements from multiple clauses. After the fieldwork, you review your evidence against the clause structure to identify any gaps. If you have not gathered any evidence against Clause 9.1.2 (customer satisfaction monitoring), for example, you know you need to go back and ask about it.
This combined approach gives you the depth and realism of process based auditing with the completeness assurance of clause based auditing. It is the approach recommended in ISO 19011, the guidelines for auditing management systems, and it is what experienced certification auditors use in the field.
Practical Tips for Shifting to Process Based Auditing
If you have been conducting clause based audits and want to shift to a more process based approach, here are some practical steps to make that transition.
- Start with process mapping. Before the audit, ask the organisation for a process map or create one from your own review of their documented information. Identify the key value-adding processes and select two or three as your primary audit focus.
- Build your checklist around process steps, not clauses. Instead of asking does the organisation have a documented procedure for X, ask show me what happens when Y occurs. Your questions should follow the process flow.
- Follow the evidence, not the agenda. If an auditee mentions something unexpected, pursue it. Process based auditing requires flexibility. The most significant findings often come from following a thread that was not in your original plan.
- Use sampling strategically. Select specific work orders, incidents, purchase orders, or customer complaints and trace them through the system. This grounds your audit in real transactions rather than generic capability claims.
- Cross-reference to clauses at the end. Once you have gathered your evidence, map it back to the relevant clauses. This ensures completeness and makes it easier to write your nonconformity reports with clear clause references.
When Clause Based Auditing Is Still the Right Tool
It would be wrong to dismiss clause based auditing entirely. There are specific situations where it is the more appropriate approach.
When you are conducting a document review or a desktop audit, working through the clauses systematically makes sense. You are checking whether documented information exists and whether it addresses the requirements of the standard. That is a clause based task.
When you are auditing a support function that does not have a clear process flow, such as management review, internal audit, or competence management, a clause based approach is often more practical. These are system elements rather than operational processes, and auditing them against the specific clause requirements is logical.
When you are training new auditors, clause based auditing provides a useful starting point. It helps them understand what the standard requires before they develop the confidence to follow process flows and make judgements about where to probe deeper.
The key is recognising that clause based auditing is a tool, not a methodology. It works well for specific tasks. It falls short as a complete audit approach because it does not test the system as it actually operates.
A Real World Example: Auditing a Procurement Process
To make this concrete, consider how a clause based and a process based auditor would approach the same procurement function in a manufacturing company.
The clause based auditor goes to Clause 8.4 and asks: Does the organisation have criteria for evaluating suppliers? Is there an approved supplier list? Are supplier evaluations documented and retained? Are externally provided products and services controlled? The quality manager produces the approved supplier list, a folder of supplier evaluation forms, and a purchasing procedure. The clause gets ticked.
The process based auditor asks the purchasing officer to walk them through the last five purchase orders for a critical raw material. They look at how the supplier was selected, what specifications were communicated, how delivery was received and inspected, how any quality issues were raised and resolved, and how the supplier's performance is reflected in the next evaluation cycle. In the process, they discover that two of the five purchase orders went to a supplier not on the approved list because of a stock shortage, that the incoming inspection records are missing for one delivery, and that a quality issue raised six months ago was never formally closed. The process based auditor finds the same clause reference (8.4) but with evidence that actually reflects how the system performs.
This is the difference that matters. One approach confirms that documents exist. The other tests whether the system works.
Exemplar Global Recognised Training ProviderRTP No. 310970Building Process Based Auditing Into Your Audit Programme
For internal audit programmes, shifting to a process based approach also changes how you plan your annual schedule. Rather than allocating audits by clause, you allocate them by process. You might audit the design and development process in quarter one, the production and delivery process in quarter two, the supplier management process in quarter three, and the performance evaluation and improvement processes in quarter four. Over the year, you cover all the relevant clauses, but you do it in a way that reflects how the organisation actually works.
This approach also makes it easier to apply risk based thinking to your audit programme. High risk processes get more audit attention. Processes that have had recent incidents, customer complaints, or significant changes get prioritised. This is exactly what ISO 9001 Clause 9.2 and the guidance in ISO 19011 expect from a well-designed internal audit programme.
If you are responsible for building or managing an internal audit programme, understanding the difference between process based and clause based auditing is foundational. Knowing how to audit a process you have never seen before is a skill that takes practice, but it starts with understanding that your job is to follow the work, not the standard.
How Auditor Training Develops Process Based Thinking
One of the most common observations from experienced auditors coaching newer colleagues is that clause based auditing is a habit, not a methodology. It develops because training programmes often teach the standard clause by clause, and auditors carry that structure into the field. Breaking the habit requires deliberate practice and, ideally, training that is built around process based scenarios from the start.
Good auditor training should include practical exercises where participants follow a process through from start to finish, identify the relevant standard requirements as they go, and write findings that are grounded in process evidence rather than document checklists. This is the kind of practical, scenario-based learning that actually changes how people audit.
At Audit Workshop, the Internal Auditor and Lead Auditor courses for ISO 9001, ISO 14001, and ISO 45001 are built around this practical approach. The training is designed by Dilawar Laghari, a certified lead auditor with over 14 years of compliance experience and more than 500 external certification audits conducted across Australia, the Middle East, and South Asia. The courses focus on how auditing actually works in the field, including how to structure a process based audit, how to follow evidence where it leads, and how to write findings that are clear, defensible, and useful. If you want to move beyond checklist auditing and develop real auditing capability, the courses at Audit Workshop are a practical place to start.










