Mandatory Audit Questions
Are procedures being audited meeting the requirements of the where applicable e.g., ISO 9001:2015 and customer-specific codes of practise?
Are documents accessible and readily available on the master register?
Are documents in use the correct revisions?
Have the relevant staff been trained on these documents?
Are training records up-to-date with the current documents?
Previous Audit Reviewed?
Any NC Raised in Previous Audit Closed?
Audit Specific Questions
Has the organization identified which resources it needs to make available in order to ensure the effective operation of your QMS including raw materials, infrastructure, finance, personnel and IT
Has the organization considered the need for external resources in addition to the need for internal resources.
Does the management review minutes include evidence of resource allocation.
How are resource requirements reviewed – Identify staffing needs versus headcount HR
Are competencies required for each position defined
Are job descriptions appropriate
Has the organisation outlined the recruitment and selection process
The organisation identified initial training requirements
Are training files developed for each employee, including management identifying and tracking employee training requirements
Does the organisation verify that the personnel have received the planned training
Has the organization determined, provided, and maintained the infrastructure for the operation of processes to achieve product and service conformity – building, tools, equipment, utilities, IT etc
Does the organisation managed & control work environments required to achieve product conformity
Has the organisation determined the continued improvement of the facility through informal or formal review meetings
Is there good lighting, ventilation, safe passageways, stairs and corridors
Are working equipment, tools and process maintained
Are safe methods of work in place – observe
Has the organisation provided safe means for handling, storage, use and transportation of equipment, materials and chemicals
Has Top management provided the leadership & direction for establishing strategies to use organizational knowledge and policies and objectives
Has the organization identified the scope of organizational knowledge relevant to its business and related risks and opportunities associated with each type of organizational knowledge
Has the organization defined the process needed to manage organizational knowledge - identify, obtain, accumulate, store, communicate, use, maintain, protect and evaluate the performance of organizational knowledge management against objectives
Has the organization defined roles, authority and responsibilities for organizational knowledge process activities
Has the organization determined competency requirements and provided appropriate training and awareness for all employees using organizational knowledge
Has the organization established processes for communication, participation and consultation
Has the organization determined the nature and extent of documentation required to manage organizational knowledge
Has the organization identified any applicable regulatory and other requirements
Has the organization defined & implemented an organizational knowledge change management process?
Has the organization performed organizational knowledge activities – assign responsibilities, identify, obtain, accumulate, store, maintain, protect, communicate, use and evaluate the performance of organizational knowledge?
Has the organization tracked organizational knowledge performance measures?
Does the organization investigate loss, irretrievability or theft of organizational knowledge
Has the organization evaluated compliance to applicable regulatory requirements
Has the organization maintained appropriate records of organizational knowledge management activities
Has the organization verified achievement of organizational knowledge goals and objectives
Is there a documented list of equipment & its location
Are devices identified in such a way that the user can determine that the device has current calibration; i.e marked in accordance with calibration requirements
Are devices calibrated at a pre-determined intervals or prior to use
Are devices calibrated by external providers certified to ISO 17025
Are devices calibrated to a defined method, traceable to a national or international standard [where there is no standard available for the device the basis for calibration or verification must be recorded]
Are records of calibration maintained – sample check
Are records of verification maintained – sample check
Are devices safeguarded from adjustment, which may invalidate results
Are devices protected from misuse & handled and stored in a manner to protect the equipment from damage through design or the training of staff
Are procedures in place to record actions to be taken when the prescribed devices are found not to be operating within specified limit
Equipment found to be out of calibration are adjusted/re-adjusted by qualified personnel
Computer software which is used for monitoring/measuring is validated prior to initial use;
Computer software used for monitoring and measuring is re-validated where necessary
Has the organization summarised major training initiatives and activities planned for the given budget year?
Have employee training needs been identified? Including existing workers, new hires, temporary workers and outside contractors?
Are training plans developed, implemented? Have competency-based training needs been identified - Review training plans for selection
Are training plans reviewed regularly to ensure that they are up to date and meet current demands.
Is training scheduled and prioritized according to the needs of the work area
Where established has training been undertaken before commencement of work
Are training requirements for employees assessed against wider organizational policies and objectives.
Are abilities and competencies of workers monitored?
Are training needs determined during the appraisals process?
Are suitable training matrices produced for each workplace?
Are legislative requirements, including license requirements or management system requirements identified e.g. IFS training needs
Is Employee training and re-training recorded, monitored and kept up to date by their Line Manager and Supervisor
Is a training register containing information on specified levels of education, training, and experience established for each employee whose work is involved with any significant impact and safety hazard
Does training material emphasize responsibility for minimizing significant impacts and risks associated with their work
Does training material identify potential consequences of departures from specified operating procedures & address the benefits of improved personal performance
How is competency evaluated or demonstrated e.g., through tests, observations, results
Is the person performing the activity able to demonstrate his or her competencies?
If the person is found not to be competent, how does the organisation take action to raise competence to the required level
Is on-the-job training provided by a more experienced employee or by an external trainer, skilled in the requirements of that particular activity as indicated by their training record
Are training plans updated on a regular basis by the Line Manager to reflect the training status
Are employees encouraged to request further training to aid their personal development
Has the organisation considered its future needs?
Do employees understand the importance of conformance with the quality policy and the management system procedures and requirements
Is awareness training undertaken [broad-based training provided to increase employee awareness]
Does awareness training material include key elements of the management system
Does awareness training material include the importance of compliance with operational and regulatory requirements
Does awareness training material include the overall improvement aims of the management system
Does awareness training material include the importance to interested parties
Are records of attendance at awareness training available
Do employees understand their role for minimizing significant impacts and risks associated with their work
Are procedures established to make employees aware of the benefits of personal performance
Are procedures established to make employees aware of their roles and responsibilities in achieving conformance with policies and procedures
Are procedures established to make employees aware of the benefits of the potential consequences of departure from specified operating procedures
Do all new recruits (workers, contractors and temporary staff) receive induction training or briefings
Does training programmes including Tricel core values and policies, company overview & history, the people and structure, contract of employment, induction pack, health, safety and environmental briefing
Are induction records completed, signed by each participant & retained – sample check
Where tool-box-talks are used for general awareness training is there an attendance list completed & signed by each participant
Is the person providing the tool box talk documented on the records.
Has the organization identified the necessary internal and external communications that are required for the operation of the management system
Has the organisation identified when & how communications will occur?
Your organisation needs to ensure that procedures to control internal and external communications and interfaces are in place include enforcement authorities, lawyers/solicitors, insurance companies
Do all documents have identification?
Do all documents have an appropriate format? Date, title, revision number etc
Have all documentation been reviewed and approved?
Are all documents in the correct place?
Is all documented information protected from tampering, unauthorized changes, and damage?
Is documented information available in the correct language?
Are employees able to access all documentation easily?
Has the organisation specified where all documentation is located?
Is the organization able to ensure that the correct versions of documented information are available?
How long does the organisation retain documentation? Does the retention period meet customer and regulatory requirements
Does the documented information guide the production of products provided by the organization?
Is documented information of external origin used for the development of the QMS controlled – standards available, of the correct version
Are records legible, completed in real time & in good condition?
Are any alterations to records authorised & recorded?
Are records appropriately verified [include signature of operator or supervisor verifying records]
Are records maintained & retrievable?
Are records completed in a manner that accurately transmits the intended information
Where records are in electronic form are these suitably backed up?
Are electronic records controlled? e.g., Security policy, password rules, storage and back-up policy including protection from loss, corruption, physical damage
Are authorisation levels for amending electronic documents defined to prevent unauthorized changes, unintended alteration?
Does the organisation test electronic retrieval systems & are records of tests retained?
PN111 - 6) Does the organisation hold and update a register of "Critical Components"?
PN111-6) Does the organisation maintain a master list that details all QMS documents?
