The Audit Trail Auditors Actually Follow, Question by Question

Auditors follow one chain. Show me a finished job. Who performed it. Were they certified for that method on that date. What procedure revision applied. Who reviewed and approved it. Was the instrument in calibration that day. OSHA already mandates five items in writing: the date, the person's name, the equipment identifier, a description of the test and its result.

An audit is not a survey of your quality manual. It is a depth test on one job. The auditor picks a completed report, then walks backwards through every claim it makes until something cannot be evidenced. The order is stable across regimes because the logic is: a result is only as good as the person, the procedure and the instrument behind it. OSHA's process safety rule states the minimum outright — each inspection and test must be documented with the date, the name of the person who performed it, the serial number or other identifier of the equipment, a description of the test and the result. ISO/IEC 17025 adds technical records, reporting and nonconforming-work clauses on top. Aerospace adds NAS 410 and Nadcap. Nothing in that chain is exotic. Firms fail it because the six answers live in six different places.

Source: Verified against 29 CFR 1910.119(j)(4), OSHA process safety management inspection and testing, including (j)(4)(iv) which requires documentation identifying the date, the name of the person who performed the inspection or test, the serial number or other identifier of the equipment, a description of the inspection or test performed, and the results; ISO 9001:2015 clauses 7.1.5, 7.2 and 7.5.3; ISO/IEC 17025:2017 clauses 7.5 technical records, 7.8 reporting and 7.10 nonconforming work; ASNT SNT-TC-1A written-practice model; NAS 410 and Nadcap NDT audit criteria for aerospace scope.

Technically reviewed by Anoop Rayavarapu — ASNT NDT Level III (UT, RT, MT, PT, VT, ET) · API 653 · ISO 9001:2015 Lead Auditor
The audit chain in the order it is walked, and the record that answers each link
OrderThe questionRecord that answers itWhere firms fail
1Show me a finished jobThe released report, tied to a job numberReport exists; the working data behind it does not
2Who performed itA named technician on the record, not a company nameInitials only, or a crew listed without individual roles
3Were they certified for that method on that dateDated certification history plus the annual vision examOnly current status is stored, so the past date is unevidenced
4What procedure did they work toProcedure number and the revision in force on the job dateReport cites the procedure but not the revision
5Who reviewed and approved itAuthenticated approval by a person with delegated authorityApprover held no documented authority for that method
6Was the equipment in calibrationInstrument serial number linked to a certificate covering the dateInstrument identified by model, never by serial number
7How do you know that is all of itControlled record index showing completeness and retentionRecords sit in three systems that were never reconciled
The wording changes with the regime — ISO 9001, ISO/IEC 17025, Nadcap, OSHA PSM, client specification. The chain and its order do not. Question 7 is asked only when the first six wobble.

The chain is the same whatever badge the auditor wears

ISO 9001 registrar, ISO/IEC 17025 assessor, Nadcap auditor, client quality representative, insurance surveyor — the vocabulary differs and the sequence does not. Every one of them is testing the same proposition: that a stated result was produced by a qualified person, following an approved method, with a controlled instrument, and reviewed by someone entitled to release it. Break any link and the result is an opinion.

That is why preparing for a specific standard is less useful than preparing for the chain. A firm that can walk any job backwards through six questions satisfies ISO 9001 clause 7.2 on competence, clause 7.1.5 on monitoring and measuring resources, and clause 7.5.3 on control of documented information without treating them as three separate exercises. The chain satisfies the clauses; the clauses do not build the chain.

The regimes differ only in what they hang on top. ISO/IEC 17025 adds technical records at clause 7.5 and reporting at 7.8. OSHA process safety management adds a statutory minimum record content for covered equipment. Aerospace adds NAS 410 personnel qualification and Nadcap audit criteria. Each is an extra requirement fastened to the same six-link spine, and each is easier to meet once the spine holds.

Question one: show me a finished job

The audit begins with a sample, not a survey. The auditor asks for a list of jobs completed in a period, picks one — often deliberately awkward, a job at a remote site, or one near a year boundary — and asks for the released report. Everything after this is a trace backwards from that document. The selection is not random in spirit: awkward jobs are where systems leak.

The first failure happens here more often than firms expect. The report is produced, and the working data behind it is not. Field sheets are in a truck, the raw scan files are on a technician's laptop, or the report was assembled from a phone photo of a handwritten sheet that nobody kept. A report without its underlying data is a claim, and the auditor will say so before moving to question two.

Fix this by making the report a view of stored data rather than a document typed separately from it. When capture and report share one record, question one is answered by pulling up the job, and the traceability that follows is a property of the system rather than a filing exercise. The test is simple: can you open the job and see the raw readings that produced the conclusion, without opening a second application? If not, the report and the evidence are two artefacts that can disagree.

Question two: who did it

The auditor wants a person, not a company. Reports that name the firm, or carry initials without a mapping to a personnel file, stall the audit immediately. OSHA's process safety rule makes the point statutorily for covered equipment — the documentation must identify the name of the person who performed the inspection or test. Firms working refinery and petrochemical scope inherit that requirement through their client's mechanical integrity programme, whether or not their own quality manual repeats it.

Crews create the specific trap. A two-person team shoots a job and one signs. If the signer performed the interpretation and the second person handled the equipment, the record has to say so, because question three will ask about the certification of whoever did the interpreting. Vague attribution at question two becomes an unanswerable question three. Record the role each person held, not just the names on the sheet.

The fix is a single field bound to a controlled personnel list, not a free-text name box. Free text produces 'J. Rodriguez', 'Rodriguez J', and 'JR' for the same technician across eighteen months, and nobody can prove they are one person without a database join that does not exist. A dropdown bound to the personnel record costs nothing to implement and removes an entire category of finding.

Question three: were they certified for that method on that date

This is where most findings are written. Not because firms employ uncertified technicians — they rarely do — but because the evidence is stored as a present-tense fact. The certification folder holds a current certificate. The auditor asked about a date fourteen months ago. Those are different questions, and the second decides whether the inspection stands. A current certificate proves nothing about a job closed last spring.

The complete answer has four parts: the method certification covering that date, the level appropriate to the task performed, the annual near-vision examination current on that date, and any client or site qualification the contract required. SNT-TC-1A places recertification at intervals not exceeding five years through the employer's written practice; the vision examination runs on a twelve-month cycle and is the part most frequently missing from the file.

Firms that answer this instantly hold dated certification history and can query it as of any date. Firms that struggle hold a folder of PDFs. The difference is not effort — it is where the certification records live and whether the system can evaluate a past state rather than only display a current one. Ask your own system for a technician's eligibility as of a date last year; the answer takes seconds or it takes a week.

Question four: what procedure did they work to

The report cites a procedure. The auditor asks for the revision that was in force on the inspection date, then reads it against what the report records — technique, calibration block, scan plan, acceptance criteria. Mismatches between the procedure and the recorded parameters are the second most common finding after certification dates. He is not testing whether the procedure is good; he is testing whether it was followed.

Two structural problems create most of them. Procedures are revised without archiving the superseded version, so the in-force revision cannot be produced at all. And report templates are not updated when procedures change, so a report keeps recording a parameter the current revision no longer requires, or omits one it now demands. Both are document-control failures rather than technical failures, and both are cheap to fix before an audit and expensive afterwards.

A related question surfaces here for weld work: whether the method chosen was appropriate to the flaw type and geometry. An auditor who sees ultrasonic testing specified where the client's code expects radiography will ask why, and the answer needs to be a documented technical justification signed by the Level III, not a preference or a scheduling convenience. Put the justification in the procedure. It is the difference between a considered decision and an improvised one, and auditors can tell the difference in about a minute.

Question five: who reviewed and approved it

Approval is a control, and controls have to be evidenced. The auditor looks for identity, authority and timing. Who signed. Whether that person held delegated authority for that method and level at that time. And whether the approval preceded release of the report to the client. The third element catches more firms than the first two, because reports go out under deadline pressure and the signature follows on Monday.

The authority matrix is the artefact most firms cannot produce. It is a simple table — person, method, level, scope of approval authority, effective dates — and its absence turns every signature into an unverified claim. Where a Level III is the approving authority, the audit also tests whether that Level III was accessible and current, which is a live issue for firms relying on a part-time or contracted Level III without documenting the arrangement.

Firms without an in-house Level III solve this with a documented retained arrangement and a written scope of authority. An outsourced ASNT Level III is a legitimate answer at audit when the delegation is written down, the person is named, and the reviews are dated. It is not an answer when the arrangement is informal, and auditors ask the question precisely because informal arrangements are common.

Question six: was the equipment in calibration

The auditor moves from people to instruments. He wants the serial number of the specific unit used, and a calibration certificate whose validity period covers the inspection date. Model numbers are not enough — a firm with four flaw detectors of the same model has four separate calibration states, and only one of them was in the field that day. Probes, cables and wedges carry their own identities and their own findings.

ISO 9001:2015 clause 7.1.5 covers monitoring and measuring resources, including measurement traceability where it is a requirement or is considered essential. In practice this means a documented traceability chain from your instrument to a recognised standard, plus records showing the instrument was verified before use. Calibration blocks and reference standards fall inside this scope as well, and are the items most frequently omitted from calibration registers entirely.

The recurring failure is that the calibration register and the job record are separate systems, so nobody links serial numbers to jobs at the time of the inspection. Reconstructing it eighteen months later is guesswork dressed as evidence. Linking instrument calibration status to the job at dispatch makes question six a lookup instead of an investigation.

The seventh question, asked only when the first six wobble

If the chain holds, the audit moves on. If it wobbles — retrieval takes an hour, two systems disagree, a record is produced from an email rather than a system — the auditor asks a different question: how do you know this is all of it. That is a completeness question, and it is much harder to answer than any of the six that preceded it.

Completeness is evidenced by control of records rather than by the records themselves. ISO/IEC 17025 handles this through technical records at clause 7.5 and the management system requirements in section 8; ISO 9001 handles it at clause 7.5.3. What the auditor tests is whether records are identified, protected, retrievable and retained for a defined period, and whether you can demonstrate that none were lost or altered along the way.

Once question seven is asked, the sample widens. One awkward job becomes six, then a review of a whole contract. Firms describe this as the audit going badly. What actually happened is that retrieval friction at question one signalled a systemic weakness, and the auditor followed the signal exactly as he was trained to.

Rehearse the chain before somebody else runs it

Run a mock audit on your own work this month. Pick three closed jobs at random — one recent, one from last year, one from a remote site — and have someone who did not work on them walk all six questions with a stopwatch. Record where they stop, what they had to phone somebody about, and how long each answer took to produce.

The output is a list of exactly the findings a client auditor would raise, in the order they would raise them, at zero commercial cost. Most firms discover the same pattern: questions one, two and five are fine, and three, four and six are slow because personnel, procedure and calibration data live outside the job record. That is a data-architecture problem wearing a compliance costume.

If you want the rehearsal run by someone who has sat on the other side of the table, a program audit and gap assessment does exactly this against your regime and your own evidence, and produces the remediation order rather than just the list. Ask for a walkthrough with three job numbers ready and the chain gets tested on real work, not on a checklist.

Why do auditors start with a finished job instead of the quality manual?

Because the manual describes intent and the job reveals practice. Reading a procedure proves you wrote one; tracing a completed report proves the procedure was followed on a real Tuesday by a real technician. Sampling a job also lets one thread test personnel, procedure, equipment and approval simultaneously, which is a far more efficient use of the auditor's day.

What does OSHA actually require an inspection record to contain?

29 CFR 1910.119(j)(4)(iv) requires the employer to document each inspection and test performed on covered process equipment, identifying the date, the name of the person who performed it, the serial number or other identifier of the equipment, a description of the inspection or test performed, and the results. That single clause answers three of the six links outright.

What is the most common failure at question three?

The tracker stores current status only. Asked whether a technician was certified on 14 March last year, the firm can prove he is certified today and cannot prove anything about March. Auditors treat that as an unevidenced control, because it is. Dated certification history, including the annual vision examination, is what turns the answer from an assertion into a record.

Why does the procedure revision matter more than the procedure number?

Because procedures change and reports outlive revisions. A report citing Procedure UT-04 is unverifiable if UT-04 has been revised three times since the job. The auditor needs to read the revision that was in force on the inspection date and confirm the recorded parameters match it. Revision control on procedures is what makes a two-year-old report readable at all.

What makes an approval signature defensible?

Three attributes: identity, authority and date. The record must show who approved it, that the approver held delegated authority for that method at that time, and when the approval happened. A scanned signature block with no authority matrix behind it fails the second test, and a signature applied after the report was issued fails the third.

How long does the whole six-question chain take an auditor to walk?

Twenty minutes when the records are linked, and the rest of the morning when they are not. The time is not spent reading; it is spent waiting while somebody opens a second system, then a shared drive, then calls the QA manager. Auditors read that retrieval time as a signal and widen the sample accordingly.

Request a consultation