Exemplar Global Certified Courses from USD 99. Ending Soon!

What Is a Follow Up Audit and Why It Matters in ISO Auditing

AW

Team @ Audit Workshop

13 min read
What Is a Follow Up Audit and Why It Matters in ISO Auditing

A follow up audit is one of the most misunderstood steps in the audit process. Many organisations treat it as a formality, something to tick off before the next scheduled audit. But in practice, a well conducted follow up audit is where you find out whether your corrective actions actually worked, or whether the same problems are about to resurface. If you are managing an internal audit programme or working as a lead auditor, understanding what a follow up audit is, when to conduct one, and how to run it properly will make a real difference to the value your audit function delivers.

This article covers the purpose of follow up audits, how they differ from regular audits, what triggers them, and exactly how to conduct one without wasting everyone's time.

What Is a Follow Up Audit?

A follow up audit is a targeted audit conducted to verify that corrective actions taken in response to previously identified nonconformities have been implemented effectively. It is not a full system audit. Its scope is narrow and specific, focused entirely on the findings from a prior audit and the actions the organisation took in response.

The term appears in ISO 19011:2018, the guidelines for auditing management systems, which notes that the audit client should determine whether to conduct a follow up audit as part of the audit programme. ISO 17021, which governs certification body audits, also addresses follow up activity, particularly when major nonconformities are raised during certification or surveillance audits.

In plain terms, a follow up audit answers three questions:

  • Was the corrective action actually implemented?
  • Was the root cause properly addressed?
  • Has the corrective action been effective in preventing recurrence?

If the answer to any of those three questions is no, you have more work to do. A follow up audit makes that visible before it becomes a bigger problem.

Follow Up Audits vs Regular Audits

It helps to be clear about what a follow up audit is not. It is not a repeat of the original audit. It does not cover the entire scope of the management system. It does not assess new areas or generate new findings unrelated to the original nonconformities, although a competent auditor who notices something significant during a follow up will always record it.

A regular internal audit is planned in advance as part of your audit programme, covers a defined scope, and generates its own findings. A follow up audit is reactive, triggered by previous findings, and its scope is determined by those findings. The two serve different purposes and should not be confused.

That said, some organisations choose to combine follow up verification with their next scheduled audit. This can work in practice, but it carries a risk. If you wait until the next scheduled audit to verify corrective actions, you may be waiting six or twelve months. By then, the problem may have compounded, or the corrective action may have drifted without anyone noticing. For significant nonconformities, a dedicated follow up audit is nearly always the better choice.

What Triggers a Follow Up Audit?

Follow up audits are triggered by findings that require verification. Not every audit finding automatically triggers a follow up audit. The decision depends on the nature and severity of the finding.

Major Nonconformities

A major nonconformity is a significant failure of the management system, either a complete absence of a required element or a systemic breakdown that puts the system's integrity at risk. When a certification body raises a major nonconformity during a certification or surveillance audit, the organisation must submit a corrective action plan and evidence of implementation within a defined timeframe, typically 30 to 90 days. The certification body will then conduct a follow up audit, often a remote document review or an on site visit, to verify that the corrective action has been implemented and is effective.

For internal audits, a major nonconformity should also trigger a follow up. The timeframe will depend on your organisation's corrective action procedure, but waiting until the next annual audit is rarely appropriate.

Minor Nonconformities With Systemic Risk

A minor nonconformity is a single isolated failure that does not indicate a systemic breakdown. In many cases, minor nonconformities are verified through document review at the next scheduled audit. However, if a pattern of minor nonconformities points to a deeper systemic issue, a follow up audit may be warranted to confirm the root cause has been addressed.

Observations and Opportunities for Improvement

Observations and opportunities for improvement do not typically trigger follow up audits. They are recorded, communicated, and tracked through the management review process. However, if an organisation has committed to acting on a specific observation, it is reasonable to verify that commitment at the next audit opportunity.

Certification Body Requirements

When you are working within the third party certification cycle, the certification body sets the rules. After a major nonconformity, the certification body will define the timeframe and method for follow up verification. This may be a desktop review of submitted evidence, a remote audit, or an additional on site visit. The organisation does not get to choose. Understanding this process is important for anyone preparing for a certification audit for the first time.

How to Conduct a Follow Up Audit

The mechanics of a follow up audit are simpler than a full system audit, but the rigour required is the same. Here is how to approach it in practice.

Step 1: Review the Original Findings

Start with the original nonconformity reports. Read them carefully. Make sure you understand exactly what was found, which clause of the standard was not met, and what the evidence was. If the original finding was vaguely worded, you are going to have trouble verifying the corrective action. This is one reason why writing nonconformance reports that actually drive change matters so much at the front end of the audit process.

Step 2: Review the Corrective Action Plan

Before you conduct the follow up, review the corrective action plan submitted by the auditee. Look for:

  • Whether the root cause has been identified, not just the symptom
  • Whether the proposed actions address the root cause
  • Whether the actions have been assigned to a responsible person with a due date
  • Whether the actions have been completed or are still in progress

A corrective action plan that says “retrain staff” in response to a systemic process failure is not addressing root cause. It is treating a symptom. You should be looking for evidence that the organisation has understood why the failure occurred and has changed something fundamental to prevent recurrence.

Step 3: Define Your Follow Up Audit Scope and Objectives

Your scope is the original nonconformities. Your objective is to verify that the corrective actions have been implemented and are effective. Document this before you start. Even for a short follow up audit, having a written objective keeps you focused and provides a record of what you set out to do.

Step 4: Gather Evidence

This is the core of the follow up audit. You need to gather objective evidence that the corrective action has been implemented and is working. Depending on the nature of the original finding, this might include:

  • Updated procedures or work instructions
  • Training records showing staff have been trained on the updated procedure
  • Records showing the process is now being followed
  • Monitoring data showing the problem has not recurred
  • Interview responses from the people involved in the process

Do not accept the corrective action plan as evidence of implementation. The plan tells you what the organisation intended to do. You need to verify that they actually did it. This distinction, between intention and implementation, is where many follow up audits fall short.

Step 5: Assess Effectiveness

Implementation is necessary but not sufficient. A corrective action can be fully implemented and still be ineffective. For example, an organisation might update its procedure and retrain staff, but if the root cause was a poorly designed process rather than a lack of awareness, the nonconformity will recur.

Assessing effectiveness means looking for evidence that the problem has not recurred since the corrective action was implemented. This is easier when there is measurable data available. For example, if the original finding was a failure to calibrate measuring equipment on schedule, you can check the calibration register to see whether all scheduled calibrations have been completed since the corrective action was implemented. If the finding was more qualitative, such as a failure to conduct adequate supplier evaluations, you may need to sample recent supplier evaluation records and interview the people responsible.

Step 6: Report Your Findings

The follow up audit report does not need to be long, but it does need to be clear. State the original finding, the corrective action taken, the evidence you reviewed, and your conclusion. The conclusion should be one of three outcomes:

  1. The corrective action has been implemented and is effective. The nonconformity is closed.
  2. The corrective action has been implemented but effectiveness cannot yet be determined. The nonconformity remains open pending further monitoring.
  3. The corrective action has not been adequately implemented or has not addressed the root cause. The nonconformity remains open and a revised corrective action plan is required.

Be direct. If the corrective action has not worked, say so. The purpose of the follow up audit is to find this out, not to give the organisation a pass because they made an effort.

Common Mistakes in Follow Up Audits

Having conducted follow up audits across a wide range of industries and management systems, there are patterns in how organisations and auditors get this wrong.

Accepting Documents Without Verifying Implementation

The most common mistake is accepting a revised procedure or a completed training register as proof that the corrective action is working. Documents are evidence of intent. They are not evidence of behaviour. Always verify that the people doing the work are actually following the updated procedure. Ask them. Observe the process if you can. Sample the records that should have been generated if the procedure was being followed.

Closing Nonconformities Too Quickly

There is often pressure, from both the organisation and the certification body, to close nonconformities quickly so the audit cycle can proceed. Resist this pressure if the evidence does not support closure. A nonconformity closed prematurely will resurface, and when it does, it reflects poorly on everyone involved.

Not Verifying Root Cause Analysis

If the root cause analysis is superficial, the corrective action will be superficial. During the follow up, ask the organisation to walk you through their root cause analysis. If they cannot explain why the nonconformity occurred at a systemic level, the corrective action is unlikely to be effective long term.

Scope Creep

Follow up audits have a defined scope. Stick to it. If you notice something concerning outside the scope of the follow up, note it separately and include it in the next scheduled audit. Turning a follow up audit into a full system review wastes time and creates confusion about what is being assessed.

Follow Up Audits in the Internal Audit Programme

If you are managing an internal audit programme, follow up audits need to be built into your programme design, not treated as ad hoc events. Your corrective action procedure should define timeframes for implementing corrective actions and the method for verifying effectiveness. Your audit programme should allocate time for follow up verification, either through dedicated follow up audits or through systematic verification at the next scheduled audit.

ISO 9001 Clause 9.2 requires that the internal audit programme takes into account the importance of the processes concerned and the results of previous audits. This means that areas with unresolved or recurring nonconformities should receive more frequent audit attention. Follow up audits are one mechanism for delivering that increased attention.

For a practical guide to designing an audit programme that incorporates follow up activity, the post on managing corrective actions after an ISO audit covers the corrective action side of this in detail.

Follow Up Audits in the Certification Cycle

For organisations working with a certification body, follow up audits after major nonconformities are not optional. The certification body will define the process, but here is what typically happens.

After a major nonconformity is raised, the organisation has a defined period to submit a corrective action plan and evidence of implementation. The certification body reviews the submitted evidence. If the evidence is sufficient, they may close the nonconformity by desktop review. If the evidence is insufficient, or if the nonconformity is complex, they may conduct an on site follow up audit before granting or maintaining certification.

For surveillance audits, minor nonconformities are typically verified at the next surveillance visit. Major nonconformities raised during surveillance may result in the suspension of certification until the nonconformity is resolved and verified.

Understanding this process is important for quality managers and HSE managers who are responsible for managing the organisation's certification. If a major nonconformity is raised and the organisation does not respond within the required timeframe, the certification body has grounds to suspend or withdraw certification. This is a real consequence that organisations sometimes underestimate.

The Link Between Follow Up Audits and Continual Improvement

Follow up audits are not just about compliance. They are a mechanism for continual improvement. When a corrective action is verified as effective, the organisation has demonstrably improved its management system. When a corrective action is found to be ineffective, the organisation has an opportunity to understand why and do better.

The organisations that get the most value from their audit programmes are the ones that treat follow up audits seriously, not as an administrative burden but as a genuine check on whether their improvement efforts are working. This mindset shift, from compliance to improvement, is what separates a functioning management system from one that exists only on paper.

If you are building your skills in this area, understanding how to verify corrective action effectiveness is a core competency for both internal and lead auditors. Audit Workshop's training courses for ISO internal auditors and lead auditors cover corrective action verification, root cause analysis, and follow up audit techniques in practical detail, with real audit scenarios drawn from over 500 external certification audits. If you want to build auditing skills that hold up in practice, not just in theory, that is where to start.

Frequently Asked Questions

No. A surveillance audit is a scheduled audit conducted by a certification body, typically annually, to verify that the management system continues to meet the requirements of the standard. A follow up audit is a targeted audit conducted specifically to verify that corrective actions from a previous audit have been implemented and are effective. A surveillance audit may include follow up verification of prior nonconformities, but it covers a broader scope than a dedicated follow up audit.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.