Client Audit Evidence Pack Checklist
Audits are an exercise in reconstruction. The auditor picks one issued report and works backwards: who did this, were they qualified on that date, was the equipment calibrated, which procedure revision applied, and how was the decision justified. Companies that can walk that chain quickly pass comfortably.
Almost nobody fails an audit on the technical work. They fail on the ability to produce evidence about the technical work, and specifically on point-in-time evidence — proving what was true on the day rather than what is true now. This checklist is both a preparation tool and a diagnostic. Used as a diagnostic it takes an hour: pick three issued records and try to reconstruct each completely. Whatever you cannot produce in that hour is the real scope of your preparation. It applies to client vendor audits, ISO 17020 and 17025 assessments, and customer quality audits in any regulated supply chain.
What it covers
- The issued record itself, with results located against the item examined rather than as an undifferentiated list.
- Personnel qualification as at the date of the work — not as at today.
- Vision or medical currency on that date, where the scheme requires it.
- Equipment calibration status covering the date, including accessories and reference standards.
- Traceability of those calibrations, and the accreditation scope of the body that performed them.
- The procedure and its revision in force on that date, plus the technique sheet actually followed.
- The written practice or equivalent governing personnel qualification, at the applicable revision.
- Acceptance criteria applied — the specific code, edition and clause, not just the standard name.
- The approval chain, with the reviewer or approver and their own qualification state.
- Any non-conformance raised, its disposition and its closure evidence.
- Client-specific approvals or inductions in force on the date, where the site required them.
- The reconstruction test — three records, one hour, and a written list of what could not be produced.
How to use it
Run the diagnostic before you prepare anything: Pick three issued records at random — not your best ones — and try to reconstruct each completely. The gaps you find are your actual scope, and they are almost never the gaps people expect.
Distinguish fixable from structural: A missing certificate can be obtained. An inability to determine which procedure revision applied two years ago cannot be fixed retrospectively at all, only prevented going forward. Separate the two lists, because they need different responses.
Start freezing state immediately: Even before any systems change, record the qualification and calibration state onto records as they are issued. It costs nothing prospectively and it is the single item that most often decides an audit.
Rehearse with the real checklist: Use the client or assessment body’s own checklist rather than a generic one. They will apply theirs, and the differences are usually where the findings come from.
Frequently Asked Questions
How far back will an auditor look?
Commonly the current cycle plus the previous one, which for in-service inspection can mean several years. That is why point-in-time reconstruction matters more than current-state reporting: the records being examined were created under a system, and possibly a procedure revision and a written practice, that have since changed.
What is the most common finding?
The inability to produce point-in-time evidence. The organisation can prove a technician is qualified now, but not that they were qualified on the date they signed a specific report. It is a data-model issue rather than a diligence issue, and it cannot be corrected retrospectively — which is why it is worth addressing before an audit is scheduled rather than after one is announced.
Should the same person own the pack every time?
The pack should be a query rather than a person. If assembling it depends on one individual who knows where everything is filed, the arrangement fails the moment they are unavailable — and auditors notice when a request produces a scramble. Ownership belongs with the quality function; retrieval should not depend on memory.
Does software remove audit findings?
It changes which findings are possible. Structural findings about missing point-in-time evidence, unrecoverable procedure revisions or unidentifiable examination locations largely disappear when the data model handles them as a matter of course. Findings about technique, judgement and coverage remain entirely a matter of competence and are unaffected by tooling.
See it running on your own workflow
Thirty minutes, your job types and your reporting formats, co-presented by an ASNT NDT Level III. Affordable, accessible, fully customizable — request a demo and a tailored quote.
Related: Passing an API 653 client audit · Document control that answers "which revision" · Keeping the evidence recoverable · All free resources