A desktop audit is a structured review of an organisation's documented information, policies, procedures, and records conducted away from the physical site, typically before or instead of an on-site visit. If you have ever had a certification body ask you to submit your quality manual, procedures, and risk register before the auditor arrives on site, you have already experienced the first half of a desktop audit. Understanding exactly what it involves, when it applies, and what auditors are actually looking for will help you prepare more effectively, whether you are the quality manager getting ready for a Stage 1 audit or an internal auditor designing your own programme.
On this page
The Basic Definition
A desktop audit, sometimes called a document review audit or off-site audit, is an audit conducted by reviewing documented evidence rather than by physically attending a workplace. The auditor examines documents, records, and other information submitted by the organisation or accessed through shared platforms, then draws conclusions about whether the management system meets the specified requirements.
The term is used in several different contexts, and this is where people sometimes get confused. In certification auditing, a desktop audit most commonly refers to the Stage 1 audit, where the certification body reviews your system documentation before conducting the on-site Stage 2 audit. In internal auditing, it refers to the preparatory document review phase before an auditor visits a department or process. In remote auditing, a desktop audit can be the entire audit, conducted via document sharing, screen sharing, and video interviews.
The common thread across all these contexts is that the audit is driven by documented evidence rather than direct observation of activities, people, and physical conditions.
Exemplar Global Recognised Training ProviderRTP No. 310970Where Desktop Audits Fit in the Certification Process
If you are preparing your organisation for ISO certification, the desktop audit is typically the first formal contact you have with the certification body's auditor. Under the two-stage certification process, Stage 1 is almost always conducted as a desktop review, sometimes supplemented by a short site visit to confirm the scope and understand the physical context.
During Stage 1, the auditor is not trying to catch you out. They are assessing whether your documented management system is sufficiently developed to proceed to Stage 2. They want to see that you have addressed the requirements of the standard in your documentation, that your scope is clearly defined, that your key processes are documented, and that you have completed foundational activities like internal audits and management review.
What the auditor is looking for at Stage 1 includes:
- A defined scope of the management system
- A policy that meets the requirements of the standard
- Evidence that significant aspects, risks, or hazards have been identified
- Documented objectives with measurable targets
- A completed internal audit against the standard
- Evidence that a management review has been conducted
- Key procedures and documented information required by the standard
If the documentation review reveals significant gaps, the auditor will raise these as issues to address before Stage 2 proceeds. This is actually useful. It gives you a clear picture of where your system needs work before the full certification audit begins.
For more on what happens at each stage, see our article on what happens at Stage 1 and Stage 2 of an ISO 9001 audit.
Desktop Audits in Internal Audit Programmes
Within an internal audit programme, the desktop audit phase is the document review you conduct before visiting a process or department. Most experienced internal auditors treat this as a non-negotiable part of audit preparation, not an optional extra.
Before walking into a department, a good internal auditor will have already reviewed:
- The procedures and work instructions that govern that process
- Previous audit reports and any outstanding corrective actions
- Relevant records, such as training matrices, maintenance logs, or inspection records
- Applicable clauses of the standard being audited
- Any customer complaints, incidents, or nonconformities linked to that area
This preparation does several things. It tells you where the risks are, so you can focus your limited audit time on the areas that matter most. It also tells you what questions to ask, because you already have a picture of what the process is supposed to look like and you can probe the gaps between documentation and reality. And it means you arrive at the audit with credibility. Auditees respond better to an auditor who clearly understands the process than to one who is reading the procedure for the first time during the interview.
The document review also helps you identify whether the documentation itself is adequate. If a procedure is vague, out of date, or missing entirely, that is a finding in its own right, and you want to note it before you arrive rather than discover it mid-interview.
Standalone Desktop Audits: When the Review Is the Whole Audit
In some situations, the desktop review is not just preparation for an on-site visit. It is the entire audit. This happens in a few specific circumstances.
Remote auditing became significantly more common following the disruptions of the early 2020s, and many certification bodies and internal audit programmes have retained elements of remote practice. A remote audit conducted entirely through document review, video calls, and screen sharing is essentially a desktop audit. The auditor reviews submitted documents, interviews personnel via video, and observes processes through shared screens or live camera feeds.
Supplier qualification audits are another context where desktop audits are used as standalone assessments. Rather than visiting every supplier on site, a quality manager might conduct a desktop audit by requesting the supplier's quality management system documentation, certificates, and records, then assessing conformity against defined criteria. This is a practical approach when the supplier is geographically distant or when the risk level does not justify the cost of a site visit.
For a detailed look at how supplier audits work in practice, our guide on how to conduct a supplier audit covers both desktop and on-site approaches.
Low-risk surveillance audits are sometimes conducted as desktop reviews, particularly for organisations with a strong track record and simple, well-documented systems. The certification body reviews updated records and documentation between site visits to confirm the system is being maintained.
What Auditors Actually Do During a Desktop Audit
If you have not conducted a desktop audit yourself, it helps to understand what the auditor is actually doing when they review your documents. It is not a passive reading exercise. A skilled auditor is actively looking for specific things and forming judgements about the system as a whole.
Checking for Completeness
The first pass is about completeness. Does the organisation have the documented information required by the standard? For ISO 9001, this includes things like the scope, the quality policy, quality objectives, documented procedures for specific processes, and records of internal audits and management review. The auditor will work through the standard's requirements and check off what is present and what is missing.
Assessing Adequacy
Having a document is not enough. The auditor also assesses whether the document is adequate, meaning whether it actually addresses the requirement in a meaningful way. A quality policy that simply states
we are committed to qualitywithout meeting the specific content requirements of clause 5.2 is present but not adequate. An internal audit report that lists clauses checked but provides no evidence of what was reviewed or what was found is present but not adequate.
Looking for Consistency
Experienced auditors look for consistency across documents. If your scope says you provide project management services but your procedures only cover manufacturing processes, that inconsistency tells a story. If your risk register identifies a particular process as high risk but your audit programme has not scheduled that process for audit in two years, that is another inconsistency worth noting.
Identifying Gaps for Follow Up
The desktop audit generates a list of questions and areas to follow up. Some of these will be findings in their own right. Others will be lines of inquiry to pursue during the on-site phase. A skilled auditor uses the document review to build their audit plan for the on-site visit, directing attention to the areas where the documentation raises questions.
Preparing for a Desktop Audit as the Quality Manager
If your organisation is about to undergo a Stage 1 audit or a remote audit, preparation for the desktop component is straightforward but requires attention to detail.
Organise Your Documents Logically
Auditors are busy. If they have to hunt through a disorganised file system to find your management review minutes, they will note the difficulty. Organise your documents in a logical structure that maps to the standard's clauses, or provide a clear index that tells the auditor where to find each required document. A simple document index that lists each required document, its title, its location, and its current version number makes a strong first impression and saves everyone time.
Check Currency and Version Control
Before submitting documents, check that everything is current. Out-of-date procedures, superseded forms still in circulation, and records that have not been updated for months are common issues that create unnecessary findings. A quick internal review of document currency before the audit can prevent a lot of avoidable nonconformities.
Make Sure Mandatory Records Are Complete
The standard requires specific records to be retained as evidence of conformity. For ISO 9001, this includes records of monitoring and measurement, internal audit results, management review outputs, and records of competence. Make sure these records exist, are complete, and are accessible. A management review that happened but was not documented is the same as a management review that did not happen, from an audit perspective.
Do Not Over-Document
One of the most common mistakes organisations make is creating documents for everything in anticipation of an audit, producing a bloated system that is difficult to navigate and difficult to maintain. The standard requires documented information where it is necessary to support the operation of processes and to provide confidence that the processes are carried out as planned. If a simple one-page procedure covers the requirement, that is enough. More documentation is not better documentation.
Limitations of Desktop Audits
A desktop audit is a valuable tool, but it has real limitations that every auditor and quality manager should understand.
Documentation tells you what an organisation intends to do. It does not tell you what actually happens on the floor. A beautifully written procedure for managing nonconforming products tells you nothing about whether that procedure is actually followed when a defective batch arrives. That gap between documented intent and operational reality is exactly what on-site auditing is designed to expose.
This is why desktop audits are almost always paired with on-site activities in certification auditing, and why the document review phase of an internal audit is preparation for the visit, not a substitute for it. If you conduct a desktop review and find that everything looks fine on paper, that is not the end of the story. It is the starting point for the deeper inquiry that happens when you talk to people and observe work being done.
For organisations using remote auditing extensively, this limitation needs to be consciously managed. Auditors conducting remote audits need to be deliberate about gathering evidence beyond documents, using video observation, live demonstrations, and targeted interviews to test whether documented processes reflect operational reality.
Our article on remote auditing under ISO standards covers the practical challenges and techniques in more detail.
Exemplar Global Recognised Training ProviderRTP No. 310970Desktop Audits and ISO 19011
ISO 19011, the international guideline for auditing management systems, provides guidance on how audits should be planned and conducted. While the standard does not use the term desktop audit as a defined term, it does address document review as a standard audit activity and recognises remote auditing as a legitimate audit method.
The 2026 revision of ISO 19011 gives additional attention to remote auditing and the use of digital tools, reflecting how audit practice has evolved. The principles it establishes, including evidence-based approach, fair presentation, and due professional care, apply equally to desktop reviews and on-site visits. An auditor reviewing documents remotely is still bound by the same professional obligations as one walking the factory floor.
What ISO 19011 makes clear is that the method of gathering evidence should be appropriate to the audit objectives and the context. A desktop review is appropriate for assessing the adequacy of documented information. It is not appropriate as the sole method for assessing whether operational controls are effective in practice.
Building Desktop Audit Skills
If you are developing as an auditor, the ability to conduct an effective document review is a foundational skill. It requires you to know the standard well enough to recognise what is required and what is missing. It requires you to read critically, noticing not just what a document says but what it does not say. And it requires you to connect the dots across multiple documents, identifying inconsistencies and gaps that would not be visible from any single document in isolation.
These skills are developed through training and practice. A well-structured internal auditor course will teach you how to approach document review systematically, what to look for in each type of documented information, and how to translate your review findings into meaningful audit questions for the on-site phase.
If you are considering formalising your auditing skills, Audit Workshop offers internal auditor and lead auditor training across ISO 9001, ISO 14001, ISO 45001, ISO 27001, and other standards. The courses are built around real audit practice, including how to conduct effective document reviews that set you up for a productive on-site audit. You can explore the available courses at auditworkshop.com.













