5 Questions to Ask Before Your Next Surveillance Audit

Table of Contents
5
min read

Surveillance-audit preparation often begins with a familiar checklist: review procedures, close overdue CAPAs, update the audit calendar and confirm management review is scheduled.

Those tasks matter. But they can create a false sense of readiness if the organisation has not tested whether it can retrieve and explain the evidence behind its quality processes. The following five questions provide a practical audit-readiness test.

1. Can we show the current procedure and the people who are trained on it?

Choose a critical process such as CAPA, supplier approval, document control, change control or complaint handling. Then ask:

- What is the current approved procedure?

- When did it become effective?

- Who owns it?

- Which roles need training or acknowledgement?

- Can we show that selected users completed the required training?

- Can we show how a past version was superseded and retained?

A controlled document is stronger evidence when it is connected to the people and activities it governs.

2. Can we trace one quality event from start to finish?

Select a recent nonconformance, deviation, complaint or audit finding. Can the team retrieve:

- The original event and affected scope.

- Immediate correction or containment.

- Investigation and root cause.

- CAPA or action plan.

- Owners, due dates and approvals.

- Completion evidence.

- Effectiveness review.

- Related changes, training or supplier/product/process information.

If users need to search several folders, spreadsheets and inboxes, the process may be functioning but the evidence model is weak.

3. Can we explain a recent change?

Select a recent change to a procedure, supplier, material, specification, product, process or system. Ask:

- What changed and why?

- What products, sites, processes or customers were affected?

- Who reviewed and approved the impact?

- Which documents and training were updated?

- How was implementation verified?

- Is there evidence of post-implementation review where required?

Change control is often where the connection between document control, operations, quality and training becomes visible.

4. Can we show how audit findings lead to improvement?

An internal-audit report alone does not demonstrate improvement. Select a finding and retrieve:

- The audit scope and finding.

- Assigned owner and target date.

- Corrective action or improvement plan.

- Evidence of completion.

- Effectiveness review.

- Connection to management review, metrics or broader quality planning where relevant.

This shows whether internal audits are operating as a learning mechanism rather than a compliance event.

5. Can we retrieve historical evidence without relying on individual memory?

Ask someone who did not create the original record to retrieve a historic document, CAPA, audit finding or change control. Can they explain:

- Where the authoritative record resides?

- Whether it is current, superseded, closed or archived?

- What related evidence is available?

- Why the record remains relevant?

- How the organisation retains and retrieves it?

This matters during audits, but it also matters whenever an experienced employee leaves or a cross-functional investigation begins.

Turn the questions into a mock audit

The most useful way to use this list is to run a short, timed mock audit. Choose five real examples. Assign someone outside the immediate process team to ask the questions.

A table listing six measures to track in a mock audit: time to retrieve evidence, number of systems accessed, reliance on a specific person, missing links or attachments, conflicting versions or data, and unclear ownership, each paired with why it matters

Use the results to prioritise improvement before the formal audit.

Prepare for ISO 9001:2026 with evidence, not panic

The sixth edition of ISO 9001 is scheduled for publication on 16 September 2026.[^1] The final standard and certification-body transition guidance should shape formal implementation plans.

In the meantime, these five questions are useful regardless of future clause wording. They test whether the organisation can demonstrate controlled processes, competence, corrective action, change and improvement today.

That is the foundation of audit readiness.

FAQs

What should I check before an ISO 9001 surveillance audit?

Beyond the standard checklist of reviewing procedures and closing overdue CAPAs, test whether you can actually retrieve and explain the evidence behind your quality processes: current procedures and who's trained on them, one quality event traced start to finish, a recent change and its impact, how audit findings led to improvement, and historical evidence retrieved by someone who didn't create the original record.

Why isn't a completed checklist enough to prove audit readiness?

A checklist can create a false sense of readiness. The real test is whether evidence is connected and retrievable, for example whether a nonconformance links cleanly to its investigation, CAPA, approvals and effectiveness review, rather than whether each individual task was technically completed.

What is a mock audit and how do you run one?

A mock audit is a timed test where someone outside the immediate process team asks the five readiness questions against real examples. You track time to retrieve evidence, number of systems accessed, reliance on a specific person, missing links or attachments, conflicting versions, and unclear ownership, then use the results to prioritise fixes before the real audit.

When is the new ISO 9001 edition being published, and should I wait for it to prepare?

The sixth edition of ISO 9001 is scheduled for publication on 16 September 2026. The final standard and certification-body transition guidance should shape formal implementation plans, but the five readiness questions in this piece test foundational audit-readiness capabilities that hold regardless of the final clause wording.