Audit process flowchart
Audit process flowchart covering audit programme, planning, opening meeting, evidence sampling, finding classification, corrective actions and closure.
What the audit process is
An audit follows the same shape whether it is an internal audit of your own management system, a second-party audit of a supplier, or a certification audit run by an external body. An audit programme decides what gets audited and how often. An individual audit is scoped and planned, opened with the auditee, evidenced by sampling records and observing work, and closed with a meeting and a report. Findings that come out of it become corrective action requests, and the audit is not finished until those actions have been verified. ISO 19011, the guidance standard for auditing management systems, sets out this sequence: initiate, prepare, conduct, report, complete, and follow up.
Most audits fail at the joins rather than the steps. An auditee who first sees the scope on the morning of the audit spends the day fetching records instead of answering questions. A finding written as an opinion rather than as a statement plus objective evidence gets argued about for weeks. A corrective action request closed on the strength of a signed form leaves the same nonconformity to be raised again at the next audit. And a major nonconformity that waits for the written report loses the days when containment actually mattered.
This template is a working audit lifecycle across five lanes: audit programme manager, auditor, auditee, management and quality. It includes the four decision points where audits actually branch, namely whether the evidence meets the criteria, how a finding is classified, whether the corrective action plan is accepted, and whether the implemented actions are verified as effective. The major nonconformity escalation is drawn explicitly, so it is a defined route rather than an improvisation.
What this flowchart covers
In this template
- Programme and planning across three lanes: the audit programme manager sets the annual programme and assigns an auditor, the auditor agrees scope and criteria and issues the audit plan, and the auditee confirms dates and prepares evidence before anyone arrives.
- Fieldwork in the Auditor lane: hold the opening meeting, gather evidence and sample records, then the "Evidence meets audit criteria?" decision, which sends conforming evidence straight to the closing meeting and a gap into a written finding backed by objective evidence.
- A three-way "Finding classification?" decision splitting Major, Minor and Observation, with each branch going to a different owner rather than all three landing in the same report queue.
- The major nonconformity escalation into the Management lane: agree immediate containment action before the report is written, then rejoin the same closing meeting and reporting path so the escalation is still recorded.
- Reporting and corrective action: the closing meeting, the issued audit report, corrective action requests raised by Quality, and the auditee investigating root cause and planning actions, with a "Corrective action plan accepted?" decision that returns weak plans for rework.
- Verification and closure: implement the agreed actions, then "Actions verified as effective?", which loops ineffective actions back to root cause investigation and only closes the audit and updates the programme once effectiveness is verified.
When to use this template
- Writing or refreshing an internal audit procedure for a management system such as ISO 9001 or ISO 27001, both of which require internal audits at planned intervals against a documented programme.
- Running a supplier or second-party audit programme, where the same lifecycle applies but the auditee sits outside your organisation and escalation routes need naming in advance.
- Preparing for a certification or surveillance audit, where you need to show the certification body how findings are classified, escalated and closed.
- Training new auditors and auditees on what counts as a finding, what objective evidence looks like, and what happens after the closing meeting.
- Clearing a corrective action backlog where requests are being closed on completed paperwork rather than on verified effect, which is what the effectiveness loop in this chart is for.
How it works
Rename the lanes to your real roles
Replace audit programme manager, auditor, auditee, management and quality with the functions you actually have. In smaller organisations the programme manager and quality lanes are usually the same person, so merge them rather than drawing a handoff that never happens. Keep one rule intact whatever you merge: the auditor lane must be independent of the activity being audited, because nobody can audit their own work.
Write your own nonconformity definitions at the classification decision
The Major, Minor and Observation branches are only as useful as the definitions behind them. A common split is that a major nonconformity is a systemic breakdown or the absence of a required control, a minor is an isolated lapse in a control that otherwise works, and an observation is not a nonconformity at all. Write yours next to the decision node, with an example of each, or classification becomes a negotiation at the closing meeting.
Define the escalation rule and the clock for majors
Decide who in the management lane must be told about a major nonconformity, how quickly, and what containment they are authorised to agree, such as quarantining product, stopping an activity or suspending a supplier. Then set the time limit for closing it. Certification bodies typically impose a fixed window for major nonconformities and will withhold or suspend certification until evidence of correction has been verified, so align your internal limit with whatever your certification body requires.
Set the evidence and sampling rules
Record how samples are selected and how big they are, and state that findings must pair a statement of nonconformity with the objective evidence and the clause or requirement it breaches. This is what makes a finding defensible when the auditee disagrees, and it is the difference between an audit report and a list of opinions.
Decide what verified as effective means, and who signs it
The final decision node is where most audit processes quietly break. Define effectiveness as a re-test of the activity after the action has been running for a stated period, not as receipt of a completion form, and name who performs that check. Adjust the loop if your policy is to raise a fresh corrective action request rather than reopen the original one.
Publish it as a controlled document
An audit procedure is itself auditable, and an auditor will ask which version was in force when a given audit ran. Share the approved chart where auditors and auditees will find it, keep the earlier versions, and record who approved each revision and when, so the change history of the procedure is available alongside the audit records it governs.
Frequently asked questions
What are the main stages of an audit process?
Six, in this order: establish the audit programme and schedule the individual audit; plan it by agreeing scope, criteria and dates and issuing an audit plan; conduct it, starting with an opening meeting and then gathering evidence by sampling records and observing work; generate and classify findings, and confirm them at a closing meeting; issue the audit report and raise corrective action requests; and follow up until the actions are verified and the audit is closed with the programme updated. ISO 19011 describes this same sequence as initiating, preparing, conducting, reporting, completing and following up the audit.
What is the difference between a major nonconformity, a minor nonconformity and an observation?
A major nonconformity is a systemic failure or the complete absence of a required control, or an issue serious enough to cast doubt on whether the system can deliver its intended results. A minor nonconformity is an isolated lapse in a control that otherwise works as designed. An observation, sometimes recorded as an opportunity for improvement, is not a nonconformity: nothing has been breached, but something could be done better. The major and minor split is the working practice of certification bodies operating under ISO/IEC 17021-1 rather than something ISO 19011 itself prescribes, so if you run internal audits you should write your own definitions and keep them consistent between auditors.
What happens when a major nonconformity is raised?
It escalates before the report is written. In this template the major branch goes straight into the management lane to agree immediate containment, such as quarantining affected product, halting an activity or suspending a supplier, and only then rejoins the closing meeting and reporting path. The point of containment is to limit further exposure while root cause is still being investigated; it is not the corrective action. In a certification context a major nonconformity typically has to be corrected and the corrective action verified within a defined period, and the certification body can withhold, suspend or withdraw certification if it is not.
How is corrective action verified before an audit can be closed?
By re-testing the activity, not by filing the paperwork. Correction fixes the specific instance found; corrective action addresses the root cause so it does not recur; verification confirms the corrective action actually worked. In this chart the auditor first accepts or rejects the plan, and after implementation the "Actions verified as effective?" decision either closes the audit or loops back to root cause investigation. The practical test is to sample the same activity again after the action has been in place long enough to show results. A signed completion form is evidence of completion, not evidence of effectiveness.