Audit process flowchart

Audit process flowchart covering audit programme, planning, opening meeting, evidence sampling, finding classification, corrective actions and closure.

How it works

  1. Rename the lanes to your real roles

    Replace audit programme manager, auditor, auditee, management and quality with the functions you actually have. In smaller organisations the programme manager and quality lanes are usually the same person, so merge them rather than drawing a handoff that never happens. Keep one rule intact whatever you merge: the auditor lane must be independent of the activity being audited, because nobody can audit their own work.

  2. Write your own nonconformity definitions at the classification decision

    The Major, Minor and Observation branches are only as useful as the definitions behind them. A common split is that a major nonconformity is a systemic breakdown or the absence of a required control, a minor is an isolated lapse in a control that otherwise works, and an observation is not a nonconformity at all. Write yours next to the decision node, with an example of each, or classification becomes a negotiation at the closing meeting.

  3. Define the escalation rule and the clock for majors

    Decide who in the management lane must be told about a major nonconformity, how quickly, and what containment they are authorised to agree, such as quarantining product, stopping an activity or suspending a supplier. Then set the time limit for closing it. Certification bodies typically impose a fixed window for major nonconformities and will withhold or suspend certification until evidence of correction has been verified, so align your internal limit with whatever your certification body requires.

  4. Set the evidence and sampling rules

    Record how samples are selected and how big they are, and state that findings must pair a statement of nonconformity with the objective evidence and the clause or requirement it breaches. This is what makes a finding defensible when the auditee disagrees, and it is the difference between an audit report and a list of opinions.

  5. Decide what verified as effective means, and who signs it

    The final decision node is where most audit processes quietly break. Define effectiveness as a re-test of the activity after the action has been running for a stated period, not as receipt of a completion form, and name who performs that check. Adjust the loop if your policy is to raise a fresh corrective action request rather than reopen the original one.

  6. Publish it as a controlled document

    An audit procedure is itself auditable, and an auditor will ask which version was in force when a given audit ran. Share the approved chart where auditors and auditees will find it, keep the earlier versions, and record who approved each revision and when, so the change history of the procedure is available alongside the audit records it governs.

Frequently asked questions

What are the main stages of an audit process?

Six, in this order: establish the audit programme and schedule the individual audit; plan it by agreeing scope, criteria and dates and issuing an audit plan; conduct it, starting with an opening meeting and then gathering evidence by sampling records and observing work; generate and classify findings, and confirm them at a closing meeting; issue the audit report and raise corrective action requests; and follow up until the actions are verified and the audit is closed with the programme updated. ISO 19011 describes this same sequence as initiating, preparing, conducting, reporting, completing and following up the audit.

What is the difference between a major nonconformity, a minor nonconformity and an observation?

A major nonconformity is a systemic failure or the complete absence of a required control, or an issue serious enough to cast doubt on whether the system can deliver its intended results. A minor nonconformity is an isolated lapse in a control that otherwise works as designed. An observation, sometimes recorded as an opportunity for improvement, is not a nonconformity: nothing has been breached, but something could be done better. The major and minor split is the working practice of certification bodies operating under ISO/IEC 17021-1 rather than something ISO 19011 itself prescribes, so if you run internal audits you should write your own definitions and keep them consistent between auditors.

What happens when a major nonconformity is raised?

It escalates before the report is written. In this template the major branch goes straight into the management lane to agree immediate containment, such as quarantining affected product, halting an activity or suspending a supplier, and only then rejoins the closing meeting and reporting path. The point of containment is to limit further exposure while root cause is still being investigated; it is not the corrective action. In a certification context a major nonconformity typically has to be corrected and the corrective action verified within a defined period, and the certification body can withhold, suspend or withdraw certification if it is not.

How is corrective action verified before an audit can be closed?

By re-testing the activity, not by filing the paperwork. Correction fixes the specific instance found; corrective action addresses the root cause so it does not recur; verification confirms the corrective action actually worked. In this chart the auditor first accepts or rejects the plan, and after implementation the "Actions verified as effective?" decision either closes the audit or loops back to root cause investigation. The practical test is to sample the same activity again after the action has been in place long enough to show results. A signed completion form is evidence of completion, not evidence of effectiveness.

Use this template

More in Quality and compliance process templates

More in Process map templates

Browse all Quality and compliance process templates