Audit checklist workflow: flowchart from draft to record
Audit checklist workflow flowchart template: scope and criteria, questions drafted from the clauses, checklist review and approval, evidence sampled line by line, conforming or nonconforming or not applicable, and retention.
What the audit checklist workflow: flowchart from draft to record process is
An audit checklist is a working document, not a form. It is written for one audit against one set of criteria, it is reviewed before anyone uses it, it is filled in with what was actually seen, and it is kept afterwards as part of the evidence that the audit happened. The trigger is an audit falling due on the programme with a scope and a set of criteria attached. The chart below follows that checklist end to end: the criteria fixed, the library checked for an existing revision, a question written for each requirement in scope, the record each question must see named beside it, a coverage check, review and approval by the lead auditor, issue with the audit plan, the lines worked one at a time against sampled evidence, each marked conforming, nonconforming or not applicable, findings compiled and agreed with the auditee, the report issued, and the worked checklist filed.
This is the life of the checklist, not the life of the audit programme. There is no programme planning here, no risk-based selection of which processes get audited this year, no auditor independence check and no corrective action or follow-up verification: those belong to the wider internal audit cycle, and drawing them again would bury the part practitioners actually get wrong. The chart stops at the report and at retention, and it hands off at one point only: a line marked nonconforming at "Line conforms, fails or is not applicable?" leaves this chart as a corrective action request owned by the process owner. Keeping that boundary visible matters, because a checklist is quietly capable of absorbing the whole audit: once every question has a box, people start treating the boxes as the audit. A checklist supports auditor judgement, it does not replace it, and this template is a starting point to be adapted under your own audit procedure, your own criteria and the review of a competent auditor rather than adopted as issued.
Four of the chart's eight decisions carry the process. 'Approved checklist already in the library?' sits in the Quality manager lane because reuse is a library decision rather than an auditor's: the person who owns the checklist set knows which revision is current and what last cycle's audit found against it. 'Checklist fit for the scope and criteria?' sits with the lead auditor and is the approval gate, with a rework loop back into drafting, because a checklist that leads the witness or misses a clause in scope cannot be repaired once fieldwork has started. 'Line conforms, fails or is not applicable?' is the decision the whole document exists to make, and it has three branches on purpose, since a two-way conform-or-fail sheet forces auditors to record a pass for something that was never in scope. 'Trail found outside the checklist?' is the release valve: it loops back into the working phase so that an unexpected answer adds a line, rather than being left off the record because there was no box for it.
What this flowchart covers
In this template
- Four swimlanes (Lead auditor, Auditor (checklist author), Auditee / process owner and Quality manager) across six phases: scope and criteria, draft the checklist, review and issue, work the checklist, findings and report, and retain and improve.
- An "Approved checklist already in the library?" decision in the Quality manager lane, so a reused checklist arrives with its last revision and its previous findings attached instead of being rewritten from memory every cycle.
- The drafting loop most audit charts skip: a question written for each requirement, the record it must see named beside it, and an "Every criterion in scope covered by a line?" check that sends gaps back into drafting before review.
- Checklist review as a real gate, where "Checklist fit for the scope and criteria?" either approves the draft for issue with the audit plan or returns it for rework on the questions and the sampling plan.
- The three-way "Line conforms, fails or is not applicable?" decision worked line by line under a "More lines left on the checklist?" loop, with the failing branch writing the finding against its clause and the third branch recording why the line does not apply here.
- Close-out on agreed evidence: a "Trail found outside the checklist?" release valve that adds lines during fieldwork, an "Auditee accepts the evidence?" check with a re-check that either settles the disagreement or carries it unresolved into the report, and the worked checklist filed as a record.
When to use this template
- You are writing the first audit checklist for a process and want the drafting, review and retention around it agreed before anyone starts filling in boxes.
- Your checklists are reused year after year and nobody can say which revision was worked, or what last cycle's findings changed on them.
- Auditors are returning ticked sheets with no document numbers on them, so a finding cannot be re-checked six months later.
- Auditees have started preparing only what the issued checklist asks for, and you need a rule on what is sent in advance and what is not.
- A certification or customer auditor has asked to see the worked checklists behind your internal audit reports and you need to show where they are kept.
How it works
Rename the lanes to your roles
Replace Lead auditor, Auditor (checklist author), Auditee / process owner and Quality manager with the titles you actually use. In a small organisation the lead auditor and the quality manager are usually one person, so merge those lanes rather than drawing a review handoff that never happens. Keep the auditee in a lane of its own even then, because the records and the acknowledgement come from there.
Write your criteria onto the first step
State what this checklist is compared against: the clauses of the standard, the procedure and revision in force, the customer or contract requirement, or all three. Name the sample size and how the sample is chosen at the same step. Criteria fixed after the questions are written produce a checklist that audits the author's habits rather than the requirement.
Fix the question style and the evidence column
Decide that every line carries an open question and the record it expects to see, then say so on the drafting steps. Rule out closed questions that can be answered with a yes, and give the evidence column a shape: document number, date, batch or job, and who produced it. This is the single edit that makes a worked checklist re-readable a year later.
Set the review gate and who approves it
Name the person who reviews the draft and what they are checking: coverage of every clause in scope, questions that do not lead the answer, and a sampling plan the audit day can actually carry. Decide whether the approval is recorded on the checklist itself or in the audit plan, and whether a reused revision needs re-approval or only a coverage check.
Write your not-applicable rule
Agree what may be marked not applicable, who may mark it, and what has to be written beside it. A common rule is that the reason names the scope exclusion or the absence of the activity, and that the lead auditor reviews every not-applicable line before the report is issued. Without a rule, that branch becomes the quiet exit from any awkward question.
Set retention and where the worked checklist lives
Annotate the filing step with the actual location, the naming convention and the retention period for worked checklists, sampling notes and the report. Add how confidential or personal information written on a line is protected. In the auditor's notebook is not a retention rule, and it is the answer a certification auditor will follow up on.
Walk it against a completed audit
Take two finished audits, one that ran cleanly and one that produced a disputed finding, and trace their checklists through the chart. Any step people describe that is not drawn, and any box on the chart that nobody actually performed, is the edit worth making before you publish this as your own procedure.
Frequently asked questions
What are the steps in an audit checklist workflow?
An audit falls due on the programme, and the scope, criteria and sample size are fixed. The quality manager checks the library for an approved checklist and pulls forward its last revision and findings. The auditor lists the clauses in scope, writes one open question and names the record for each requirement, and checks every criterion has a line. The lead auditor approves the draft or sends it back for rework. It is issued with the audit plan, the auditee lays out the records, and lines are worked one at a time: ask the question, record the evidence, mark it conforming, nonconforming or not applicable, and add a line if fieldwork turns up something new. Findings are compiled from the failing lines, agreed with the auditee and reported. The worked checklist is filed as an audit record, the audit is closed, and what this cycle found goes back into the checklist library for the next one.
What is the difference between an audit checklist and an audit plan?
The audit plan is the arrangement for the audit: what is in scope, against which criteria, on which dates, in which areas, with which auditors and which auditees. The checklist is the working document that carries that plan out line by line, and it is where the evidence gets written down. One is agreed with the auditee before the audit; the other is filled in during it. In ISO 19011 terms the checklist is one form of the documented information an audit team prepares for the audit, alongside sampling details, and it is prepared after the plan rather than instead of it. Keeping the two separate matters in practice, because the plan is what the auditee agreed to: an auditor who quietly extends the checklist beyond the agreed scope has changed the plan without saying so.
Does using a checklist limit what the audit looks at?
It should not. ISO 19011 lists physical or digital checklists among the documented information an audit team prepares for the audit, and says the use of these media should not restrict the extent of audit activities, which can change as a result of information collected during the audit. That is why this chart carries a 'Trail found outside the checklist?' decision after the last line is worked. The checklist is the floor of what gets examined, not the ceiling. The risk runs in both directions. An auditor working strictly to the boxes will walk past the thing an answer has just revealed, and an auditor with no checklist at all will follow whatever is interesting and leave a clause in scope untouched. The workable position is a checklist that guarantees coverage plus a stated licence to add lines, with anything added written onto the sheet so the record matches what was really examined.
What should each checklist line contain?
At minimum: the requirement the line comes from, an open question that cannot be answered with a yes, the record or activity the question expects to see, the evidence actually sampled, and the result. Evidence is the part people leave out. ISO 9000 defines audit evidence as records, statements of fact or other information which are relevant to the audit criteria and verifiable, and defines audit criteria as the set of policies, procedures or requirements that the evidence is compared against. Verifiable is the operative word: a document number, a batch, a date, a job reference or a named person can be checked again by somebody else, and a tick cannot. Naming the evidence is also what lets a finding survive the closing meeting, because the discussion moves from what the auditor felt to what the record shows.
Who approves an audit checklist and how long is it kept?
Approval is usually the lead auditor's, and on a reused checklist the practical gate is a coverage check against the criteria in force rather than a full rewrite. Organisations that maintain a checklist library often give the quality manager the master revision and the lead auditor the tailoring for a given audit; either arrangement works as long as one named person signs that the checklist covers the scope. Retention is set by your own audit programme. ISO 19011 says documented information prepared for and resulting from an audit should be retained at least until audit completion, or as the audit programme specifies, and ISO 9001 requires documented information to be retained as evidence of the implementation of the audit programme and of the audit results. In practice the worked checklists are kept with the report for the same period.