Audits And Corrective Actions

Use This Doc For

Purpose

An audit records the scope and result of an internal, external, certification, or regulatory review. Findings identify specific nonconformities, observations, or opportunities. Corrective actions turn those findings—or an incident, gap, or management review—into owned work that can be completed and then verified.

Before The Audit

  1. Define the scope, audit type, auditor, and scheduled date.
  2. Link the audit plan to the controls and evidence the auditor will need.
  3. Confirm access and sampling requirements before the scheduled date. Creating a scheduled audit can add a compliance calendar event when an employee context is available.

Findings To Verified Action

  1. Record each finding separately with its type, description, due date, and linked control where applicable.
  2. Create a corrective action from the finding. Include the problem, root cause, accountable owner, and due date.
  3. Move the action from open to in-progress while remediation is being performed.
  4. Mark it completed only when the owner has finished the work.
  5. Verify it separately. Verification records the verifier, method, date, and changes the action to verified.
  6. Resolve the finding only when the evidence and verified action support that conclusion. Complete the audit with its actual conducted/completed dates and rating.

Decisions And Consequences

What To Watch

Recovery

If an action was completed or verified prematurely, correct its status and record what remains. If the wrong control was linked, repair the link without deleting the finding. Preserve the original audit and its dates; use follow-up findings or actions for newly discovered work rather than rewriting the prior review.