The practical answer
Connect the audit question to the records and the work that actually happened.
The audit is approaching and several teams are uploading documents into a shared folder. There is plenty of material, but it is difficult to tell which file answers which question. Good audit evidence preparation is less about producing a large collection and more about making the connection between the audit scope, the relevant records and the work that actually happened.
Start with the agreed scope. An internal process review, a customer audit and a certification audit can ask different questions. Confirm the criteria and requested period with the appropriate people instead of guessing from the last audit's folder.
Build an evidence map around the questions
Take each topic in scope and identify the records that may help address it. For an inspection process, that could include the planned checks, a sample of completed records and the follow-up to selected findings. The point is to show the relationship between the process and its use.
Keep a simple index with the topic, record location, date or period, relevant site and person who can explain it. Add a brief note about scope where a document covers only part of the question. This helps reviewers avoid assuming that a record applies more widely than it does.
Do not rename or rearrange evidence so extensively that colleagues can no longer recognise it. If a separate audit collection is needed, preserve a clear connection to the authoritative record and the context in which it was created.
Choose a sample with a readable sequence
A useful sample can follow one issue from its initial observation through the response and completion check. The reviewer should be able to understand what happened without relying entirely on the person presenting it.
Include the original finding, the agreed action, the responsible person and the relevant outcome evidence. If the work is still open, show that honestly. A pending item can demonstrate the current position more clearly than an incomplete record presented as finished.
Avoid selecting only the cleanest examples if the agreed audit approach calls for a broader sample. Let the audit scope and sampling arrangements guide selection. Preparing evidence should make the review possible, not stage a version of the process that staff do not recognise.
Identify gaps before the meeting
Ask a colleague to follow the evidence map. Can they open the files, identify the current version and understand which question each record addresses? Missing permissions and ambiguous filenames are easier to resolve before the review begins.
Where evidence is missing, record the gap and the next step. Do not recreate a historic record as though it was made at the time. If a later explanation is needed, make its timing and source clear. The distinction between contemporaneous evidence and later clarification matters to an honest account.
The UK HSE notes in its management systems guidance that its inspectors consider a range of evidence and observations, rather than relying only on a claimed standard. This is a useful reminder that a document collection alone does not establish how work is managed.
Prepare the people who understand the work
Let relevant colleagues know the scope and where their records sit. They should be able to explain the normal process, including what happens when something goes wrong. They do not need a rehearsed script or a claim that every record is perfect.
If a key person will be absent, identify suitable cover and arrange a factual handover. Avoid assigning someone to explain a technical activity they do not understand merely because they are available on the day.
Check how sensitive information will be handled. Agree an appropriate way to provide necessary evidence while limiting unrelated personal or confidential details. Follow the organisation's approved arrangements and the audit's legitimate information needs.
Turn findings into work people can own
After the audit, preserve the finding in its proper context. Clarify the required response and any agreed deadlines through the audit process. Assign the resulting work to someone with a clear understanding of the issue and the support needed to act.
Keep the evidence of follow-up connected so the next review can see what changed. A folder labelled “closed” is much less useful than a record explaining the outcome.
Audits and Compliance Management are part of CerthixCO. For follow-up that has stalled, read Why corrective actions become overdue. Preparation works best when it makes everyday records easier to understand throughout the year.
← Back to the blog