Audit Preparation for Inspection Firms: Retrieval, Not Rewriting
Audit preparation is a retrieval problem, not a documentation problem. An auditor samples one finished job and traces it backwards: report, technique sheet, examiner certification on the date of examination, instrument calibration on that date, and the written practice in force. Software that stores those objects against the job number turns a multi-day binder hunt into a search.
The documents an auditor wants almost always exist. They are in five places: the report on a shared drive, the technician's certification in a Level III's folder, the calibration certificate in an email from the calibration house, the procedure in a controlled binder, and the written practice in a PDF nobody has opened since the last revision. Preparation weeks are spent walking between those five places, once per sampled job. That is why audit preparation software is measured by retrieval, not by storage. The test is a single job number returning every object attached to it, in the revision that was in force on the examination date. ISO 19011 tells auditors that evidence should be based on samples, because an audit runs in finite time with finite resources. A firm that answers the first sample completely narrows the audit. A firm that fumbles the first one widens it.
Source: ISO 19011:2018, guidelines for auditing management systems (audit evidence based on samples, finite time and resources); 29 CFR 1910.119(j)(4)(iv), OSHA process safety management inspection and test documentation, and OSHA's 1996 interpretation letter on documenting inspections and tests; 10 CFR 50 Appendix B, Criterion XVII, quality assurance records; ASNT Recommended Practice No. SNT-TC-1A §5 (written practice) and §8.2 (vision); ASME BPVC Section V, Article 1, T-120; ISO 9001:2015 clause 7.1.5.2; PRI/Nadcap AC7114 nondestructive testing audit criteria, with the most common nonconformances compiled annually and published on eAuditNet. Statements about Atlantis describe our own Odoo 18 build.
| Evidence object | Regime that names it | The traceback question it answers | Failure mode when it is missing |
|---|---|---|---|
| Final report with examiner signature and disposition | ISO 9001:2015 §8.5; client specification | Who examined this, what did they find, and did they sign it? | An unsigned report, or a report signed by a reviewer rather than the examiner |
| Personnel certification valid on the examination date | ASME BPVC Section V, Article 1, T-120, via the employer's written practice | Was this examiner certified in this method at this level on that day? | Certification current today, lapsed on the date of work |
| Vision examination record supporting the certification | SNT-TC-1A §8.2; ISO 9712 (employer verifies acuity at least annually) | Could the examiner see what the report says they saw? | An undocumented vision date, which undermines the certification behind it |
| Instrument calibration certificate covering the examination date | ISO 9001:2015 §7.1.5.2 | Was this serial number in calibration when it was used? | An out-of-tolerance finding forces re-assessment of every result since the last good calibration |
| Approved procedure and technique sheet at the revision used | ASME Section V; client specification | Was the job executed to the approved technique? | Technique revision drift, where the field practice moved and the document did not |
| Written practice revision in force at the time | ASNT SNT-TC-1A §5 | Which rules governed this certification when it was issued? | A superseded practice with no revision history to point at |
| Inspection and test record fields | 29 CFR 1910.119(j)(4)(iv); 10 CFR 50 App. B, Criterion XVII | Date, person, equipment identifier, description, result, acceptability, action on deficiencies | A record missing one mandated field is a finding regardless of the work quality |
| Nonconformance and corrective action trail | ISO 9001:2015 §10.2 | What happened to the rejects, and did the fix work? | Rejects filed separately from the job, with no disposition recorded against them |
The traceback: how an auditor actually samples
An auditor does not read your quality system. ISO 19011, the guidance auditors are trained on, states that audit evidence should be based on samples of the information available, because an audit is conducted during a finite period with finite resources, and that appropriate sampling is closely related to the confidence that can be placed in the conclusions. Sampling is not a shortcut they apologise for. It is the method. Understanding it changes what you prepare, because preparing everything to equal depth spends the weeks before an audit on documents that will never be opened.
The sample almost always starts at the end. The auditor takes a completed job, often from your own job log and often one they pick while you watch, and traces it backwards. Report first. Who signed it. Was that person certified in this method at this level on the date of examination. What instrument did they use. Was that instrument in calibration on that date. Which procedure revision governed the work. Which written practice revision issued the certification. Seven hops, one job, and each hop is a pass or a fail.
The failures compound. A firm that lands all seven hops in a few minutes gets a narrower audit. A firm that breaks on hop three gets three more jobs pulled, then a systemic finding rather than an isolated one, because the auditor now has evidence that the chain does not exist rather than evidence that one file was misplaced. This is why audit preparation is a retrieval exercise. The documents exist. The question is whether the chain between them exists as data, or only in someone's recollection of how the job ran.
The evidence pack, object by object
Different regimes name different fields, and the overlap is larger than most firms assume. OSHA's process safety management rule is explicit: the employer shall document each inspection and test performed on process equipment, and the documentation shall identify the date of the inspection or test, the name of the person who performed it, the serial number or other identifier of the equipment on which it was performed, a description of the inspection or test, and the results. Five fields, mandatory, with an expectation that the documentation is retained for the life of the process.
Nuclear work sets a parallel bar. Criterion XVII of 10 CFR 50 Appendix B requires that inspection and test records, as a minimum, identify the inspector or data recorder, the type of observation, the results, the acceptability, and the action taken in connection with any deficiencies noted. Note that last item. Deficiencies and their disposition are part of the record, not an exception log kept somewhere else by somebody else. Firms that file rejects separately from the job discover this the hard way, usually mid-audit and usually in front of a client.
Layer certification and calibration evidence on top and the pack is complete: the report, the technique sheet at the revision used, the examiner's certification valid on the examination date, the vision examination record supporting that certification, the instrument calibration certificate covering the date, the written practice revision in force, and the nonconformance trail. Seven objects. If your system returns all seven from a job number, you are prepared. If it returns four and a phone call, the audit will find the other three for you.
Point-in-time is the part that breaks systems
Operational systems answer questions about now. Audits ask questions about then. Is this technician certified? Trivial. Was this technician certified on 14 March last year, under which written practice revision, with a vision examination valid on that date, using an instrument in calibration? That question defeats most tools, because they store current state and overwrite history whenever a record is renewed. The renewal that made you compliant destroyed the evidence that you were compliant before it, and no amount of care with the workbook prevents that.
The fix is effective-dating every compliance record and never deleting a superseded one. A certification carries an effective date and an expiry. A calibration certificate carries the interval it covers. A written practice carries a revision with the dates it governed. The historical query then becomes a lookup rather than an archaeology project. This is the structural reason we hold certification tracking and calibration tracking as versioned records rather than as date columns that get typed over at each renewal.
Test your own system before an auditor does it for you. Pick a job that closed twelve to eighteen months ago and ask it who was certified, in what, under which practice revision, with which instrument serial number, on that specific date. If any answer requires opening a folder, emailing the calibration house, or asking the Level III to remember, that gap is a finding waiting to be written. The test takes ten minutes and predicts the audit outcome better than any readiness checklist you can buy.
Where the preparation weeks actually go
Firms describe audit preparation as documentation work. It is almost never documentation work. The reports were written, the certificates were issued, the calibration certificates arrived by email and were filed by someone. What is missing is the index. Preparation weeks are spent walking between five storage locations, once per sampled job, assembling by hand a chain that could have been assembled automatically at the moment the work happened, at no marginal cost to anyone.
The cost is not only the hours. Every manual reassembly is a fresh chance to file the wrong revision, to attach a calibration certificate that expired two weeks before the examination, or to present a certification that was renewed after the job and looks current on its face. Auditors read dates carefully, and a date that does not reconcile invites the next three questions. A pack assembled under time pressure by someone who did not run the job introduces errors that were never present in the original work.
Indexing to the job number at the moment of execution removes the entire category. The technician's identity, their certification state, the instrument serial number and the procedure revision are all known when the assignment is made. Capturing them then costs nothing, while reconstructing them later costs weeks of senior time. That is the highest-return change an inspection firm can make to its record keeping, and starting it requires no purchase — only a decision about what gets recorded at dispatch.
The regimes that set the cadence
ISO 9001 certification runs on a three-year cycle: a Stage 1 documentation and readiness review, a Stage 2 assessment of how the management system works in practice, then surveillance audits at the end of years one and two, and a recertification audit in year three of comparable depth to Stage 2. Preparation is therefore not an annual event but a standing state, because something external is examining your records roughly every twelve months, and the surveillance visits sample from the work you did since the last one.
Aerospace work adds Nadcap. PRI compiles the most common nonconformance reports written against each set of audit criteria each year and publishes them on eAuditNet, and the top findings against the AC7114 nondestructive testing criteria have centred on the self-audit and on calibration flow-down and procedure requirements. That is a public signal about where audits break, available before you are audited, and it points directly at the two record types this page is about rather than at anything to do with technique.
Process safety adds a third cadence. OSHA's mechanical integrity requirements make inspection and test documentation a regulatory obligation with lifetime retention, which is why we treat OSHA PSM mechanical integrity NDT as its own consulting scope rather than a subsection of quality. Refinery and chemical clients audit your records as part of their contractor management programme, and their auditors run the same seven-hop traceback a registrar does, often with more technical depth.
The mock audit that predicts the real one
Run the traceback yourself, unannounced, on a job nobody prepared. Have someone outside the quality function pick the job number from the log. Start a timer. Record where each of the seven hops lands and how long each took. Do not fix anything during the exercise, because the value is in an honest map and fixing as you go destroys the measurement you came for. Write down who you had to call and what they had to open.
Score by hop, not overall. A firm that retrieves six objects in two minutes and takes an hour on the written practice revision has one problem, not a general weakness, and one problem is cheap to solve. Aggregate readiness scores hide this and lead firms to buy a platform when what they needed was a versioned PDF and a naming convention. Repeat the exercise quarterly on a fresh random job, and the trend tells you whether the fix actually held under normal operating pressure.
Where the map shows structural gaps rather than clerical ones — a written practice that does not match the codes clients invoke, methods certified without documented experience hours, procedures never qualified for the geometries you inspect — the exercise turns into an NDT programme audit and gap assessment. That work is done against your documents by a Level III, and it is the difference between passing the audit in front of you and being ready for the next three.
What audit preparation software cannot fix
It cannot create work that never happened. If an examination was performed by someone not certified in that method, the correct response is disclosure and corrective action, not a document that says otherwise. Back-dating a certification or a calibration certificate is fraud, and the audit trail in a properly built system makes that visible rather than possible. Buy software understanding that it surfaces problems before it solves them, and that the first three months of use are usually uncomfortable for exactly that reason.
It cannot supply judgement. Whether a procedure is adequate for a given geometry, whether an indication was correctly dispositioned, whether the written practice needs revision after a code edition change — these belong to a Level III. Firms without one in house engage that competence externally, which is what our ASNT Level III consulting exists to do, including written practice authorship and procedure review. Software makes those decisions retrievable and attributable. It does not make them for you.
It also cannot protect you from over-documentation. Every promise your quality manual makes is a promise an auditor will test. A manual committing to a monthly management review that nobody performs generates a finding that would not exist had the manual committed to a quarterly one. Before automating a process, delete the commitments you do not keep and rewrite the ones you keep differently. Software enforces what you wrote, including the parts you wrote optimistically in 2019.
Preparation as a standing state rather than an event
The firms that stop dreading audits are not the ones with the thickest binders. They are the ones for whom preparation is a byproduct of running the work: certification state captured at assignment, instrument serial captured at issue, procedure revision captured at execution, and the report bound to all three at close. Nothing is assembled afterwards because nothing was ever separated in the first place, so the seven-hop traceback is a query rather than a project.
That is an operational design choice, not a documentation policy. It requires compliance data and job data to live in the same system, which is the argument for putting the whole thing inside your operating platform rather than in a document repository beside it. Atlantis builds this on Odoo 18 for inspection companies, configured to your written practice, your methods and the regimes your clients invoke — affordable, accessible and fully customisable rather than a fixed template you bend your programme around.
Start with the mock traceback. It costs an afternoon, needs no software, and produces the only requirements document worth writing: a list of the hops that failed and how long each one took. Bring that list to us and we will show you what closing each hop looks like in a live system, using your own job data rather than a demonstration dataset. Ask for a demo or a quote, and run the traceback yourself first so the conversation starts from evidence.
What does an auditor ask for first?
A finished job, usually one they select themselves from your job log. Everything else follows from it: the report, the signature, the examiner's certification on the examination date, the instrument and its calibration state, the procedure revision, and the written practice in force. Auditors sample because ISO 19011 tells them to — an audit runs in finite time with finite resources, so evidence is drawn from samples.
How far back will an audit sample reach?
Far enough that current-state systems fail. Registrars commonly sample within the running certification cycle, and process safety clients reach back much further, because OSHA expects mechanical integrity inspection documentation to be retained for the life of the process. Assume any closed job is fair game, and design records so any past date can be reconstructed exactly. That single assumption changes how you store certifications and calibration certificates.
Are scanned PDFs in folders good enough?
They satisfy retention and fail retrieval. A scanned binder holds the evidence but not the chain, so answering a point-in-time question means opening files until the right one appears. What an auditor measures is how fast the chain resolves from a job number. Index the same scans to the job, the technician, the instrument serial number and the document revision, and they become perfectly adequate.
What are the most common NDT audit findings?
PRI compiles the most common nonconformances written against each Nadcap audit criteria set annually and publishes them on eAuditNet, and the top findings against the AC7114 nondestructive testing criteria have centred on the self-audit and on calibration flow-down and procedure requirements. Both are record-keeping failures rather than technical ones, which is exactly where software moves the needle. Read the published list before your next audit.
Can software close a nonconformance we already have?
It can carry the corrective action, the supporting evidence and the effectiveness check, and prove the closure later. It cannot make the underlying event untrue. Where the finding is clerical — a calibration certificate that exists but was never indexed, a vision record filed under the wrong name — retrieval fixes it. Where the finding is substantive, the corrective action is real work and software only documents that it happened.
How does audit preparation differ from a gap assessment?
Preparation gets you through the audit in front of you. A gap assessment tests whether your programme matches the codes and client specifications you actually work to, which is a question about the rules rather than about the evidence. Firms that only prepare pass audit after audit while carrying the same structural defect, until a client's technical auditor asks a different question and finds it.
Built for any business that runs on operations
Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.
What you can run on it
- Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
- Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
- Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
- Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
- People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
- Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
- Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.
Affordable, accessible, fully customizable — and we mean each word
Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.
Industries we configure for
Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.
What happens when you get in touch
A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.
Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.