A quality management system can look organized and still be unprepared for an audit.
Procedures may be approved. Training spreadsheets may be populated. CAPA records may exist. Supplier files may have been created.
But an auditor is not only looking for documents. The real question is whether your quality system is implemented, controlled, current, and effective.
That distinction is why audit preparation sometimes becomes stressful. Organizations discover that the problem is not necessarily a missing procedure. Instead, the evidence does not line up: the procedure says one thing while employees do another, training records do not match the current revision, corrective actions remain open well past their due dates, supplier evaluations are incomplete, changes were implemented without documented evaluation, and management has little visibility into quality-system performance.
The best time to discover these issues is before the auditor does. Here are 10 signs your QMS may not be audit ready and what to do about each one.
| Warning sign | Ask yourself |
| Document control problems | Can employees immediately identify the current approved procedure? |
| Training gaps | Can you prove personnel were appropriately trained when work was performed? |
| Overdue actions | Are CAPAs, deviations, audit actions, or other quality tasks repeatedly late? |
| Recurring issues | Are the same problems happening again after they were supposedly corrected? |
| Fragmented records | Does audit evidence have to be reconstructed from several systems? |
| Supplier gaps | Can you show why critical suppliers are approved and how they are monitored? |
| Uncontrolled change | Can you demonstrate that quality impact was evaluated before significant changes? |
| Weak internal audits | Do internal audits evaluate effectiveness or mostly check boxes? |
| Weak management review | Does leadership routinely evaluate QMS performance? |
| Poor QMS visibility | Can you quickly explain the current health of the quality system? |
Note
Audit readiness is not the same as audit perfection. Findings can occur even in mature quality systems. The goal is to demonstrate that processes are controlled, problems are recognized, risks are appropriately managed, and the organization responds effectively when something goes wrong.
10 Signs Your QMS May Not Be Audit Ready
1. Employees Can't Quickly Identify the Current Approved Procedure
One of the simplest audit questions can expose a much larger problem: “Show me the procedure you use to perform this activity.”
If an employee searches through several folders, opens multiple revisions, is unsure which version is current, uses a locally saved copy, references a printed document with unclear status, or has to ask Quality which document applies, you may have a document-control problem.
The issue is not simply whether the correct procedure exists. The organization should be able to ensure that personnel have appropriate access to the current controlled information needed to perform their work.
What to fix: before the audit, identify obsolete or uncontrolled copies, confirm that active procedures are clearly distinguishable from superseded versions, verify document approval and revision histories, confirm effective dates, review access permissions, make sure employees know where controlled documents are located, and remove duplicate repositories where practical. Do not try to fix this by simply telling employees what to say during an audit—fix the underlying system.
2. Training Records Don't Match Current Document Revisions
Training is often where document-control weaknesses become visible. Consider this sequence: SOP-001 Revision 2 becomes effective, several employees are trained, SOP-001 Revision 3 is later released, the process changes, some employees receive updated training, and others continue working without evidence of training to the new revision.
During an audit, the question may not simply be “Was this employee trained?” It may become: “Was this employee appropriately trained to the procedure that was effective when this work was performed?” That is a much more demanding question.
Warning signs include training tracked manually across several spreadsheets, revised procedures that do not consistently trigger training assignments, common overdue assignments, employees who appear trained to an SOP but not the current revision, training requirements that are not clearly defined by role, and training completion dates that cannot be reconciled with work records.
What to fix: reconcile training requirements against active procedures, confirm which revisions required retraining, resolve overdue training, define who requires training and why, connect document revision and training workflows wherever possible, and verify that records demonstrate completion rather than relying solely on email confirmation. Training should demonstrate competency and readiness to perform work, not simply that someone clicked through a document.
3. CAPAs and Quality Actions Are Repeatedly Overdue
An overdue action is not automatically evidence of an ineffective QMS. A pattern of overdue actions may be.
A quality system often includes deadlines associated with CAPAs, deviations, nonconformances, audit findings, supplier corrective actions, change controls, risk actions, complaint investigations, and management-review actions. If those deadlines are routinely missed, an auditor may reasonably ask whether the process is adequately resourced and controlled.
Watch for long-open investigations, CAPAs with repeatedly extended due dates, actions assigned to former employees, overdue effectiveness checks, audit findings that remain open until the next audit, extensions without documented rationale, and issues closed administratively without clear evidence.
What to fix: do not simply close overdue records before the audit. Instead, review the backlog, prioritize based on risk, confirm responsible owners, establish realistic completion dates, document appropriate justification for extensions, escalate high-risk or chronically overdue items, and determine why actions are repeatedly becoming late. If your QMS generates more actions than the organization can realistically manage, the problem may be systemic.
4. You're Fixing the Same Problem More Than Once
A closed CAPA does not necessarily mean the problem was corrected. If the same issue continues to appear in customer complaints, internal audits, deviations, nonconformances, supplier issues, production failures, or service errors, the organization may be treating symptoms instead of causes.
This is one of the strongest signals that a corrective-action process is not working effectively. Ask whether the root cause was actually determined, whether the action addressed that cause, whether the action was implemented as planned, whether effectiveness was evaluated, whether similar problems are occurring elsewhere, and whether the issue was appropriately scoped.
A recurring problem may indicate that root-cause analysis was too shallow, the CAPA scope was too narrow, actions addressed individual errors rather than process weaknesses, effectiveness was never meaningfully checked, or similar processes were not evaluated.
What to fix: review recent recurring issues together instead of treating each one independently. Trending quality data can reveal relationships that are difficult to see when each issue exists in a separate record. An auditor finding the same problem in three places is usually more concerning than finding one isolated mistake.
5. Audit Evidence Has to Be Reconstructed From Email, Spreadsheets, and Folders
An audit often tests traceability. The auditor may ask to follow one issue through the quality system—for example, deviation → investigation → CAPA → change control → SOP revision → training → effectiveness check.
If each step is stored in a different place, producing that history may require searching SharePoint, opening Excel trackers, finding emails, locating PDFs, asking employees for attachments, reconstructing approval dates, and comparing multiple records manually. The problem is not necessarily that those tools are prohibited—the problem is whether the system provides reliable and retrievable evidence.
What to fix: choose several recent quality events and attempt to trace them from beginning to end. Ask whether you can locate every related record, whether dates are consistent, whether approvals are clear, whether you can determine what changed, identify the responsible person, show required training, and demonstrate closure and effectiveness. If Quality has to reconstruct the story manually, improve the process before the audit—this is also one of the clearest signs that a SharePoint-based QMS is becoming difficult to maintain.
6. Supplier Qualification Records Are Missing, Inconsistent, or Outdated
Organizations sometimes establish an approved supplier list but have difficulty explaining how suppliers got onto it. An auditor may ask why a supplier was approved, what criteria were used, whether the supplier is critical, how performance is monitored, when the supplier was last evaluated, what happened when performance declined, and whether outsourced processes are appropriately controlled. A spreadsheet with the supplier name and “Approved” may not tell that story.
Warning signs include suppliers added without documented qualification, inconsistent or undefined risk levels, overdue supplier evaluations, missing quality agreements where expected, expired certifications on file, supplier performance issues not connected to reevaluation, and critical and noncritical suppliers receiving identical oversight.
What to fix: prioritize the suppliers capable of materially affecting your products, services, measurements, data, or regulatory obligations. Confirm qualification basis, current approval status, risk level, relevant certifications or documentation, performance history, reevaluation requirements, and open supplier issues. Supplier controls should reflect risk—a company providing office furniture usually does not require the same controls as a contract manufacturer, critical raw-material supplier, cloud provider supporting regulated records, or calibration laboratory.
7. Changes Are Implemented Before Quality Impact Is Evaluated
Some of the most consequential quality problems begin with changes that appeared harmless: changing a supplier, replacing equipment, updating software, modifying a manufacturing process, revising a test method, moving a process to another location, changing a controlled form, changing organizational responsibilities, or updating a specification.
The change happens first. Quality evaluates it afterward. That reverses the purpose of change control.
A strong change process should consider questions such as: What is changing? Why? Which products or processes are affected? What risks could the change introduce? Are documents affected? Is training required? Is validation or qualification affected? Are customer, regulatory, or certification requirements affected? Are suppliers affected? What must happen before implementation?
What to fix: review recent significant changes and look for evidence that impact was evaluated before implementation, where appropriate. If changes routinely occur through emails or meetings without formal assessment, establish a risk-based threshold for determining which changes require formal control.
8. Internal Audits Are Treated as an Annual Checkbox Exercise
An internal audit should tell you something you did not already know. If the same checklist is completed every year with almost no findings, while external auditors continue identifying meaningful weaknesses, the internal audit program may not be effective.
Warning signs include audits that always occur immediately before the external audit, every process receiving the same amount of audit attention regardless of risk, auditors who only verify whether procedures exist, employees auditing their own work without appropriate independence, consistently superficial findings, prior problems not being considered when establishing the audit program, and audit actions that are not followed through.
What to fix: shift from “Do we have a procedure?” to questions such as: Is the process actually being followed? Is it effective? Does objective evidence support the expected outcome? Have previous problems recurred? Are risks being appropriately managed? Do employees understand their responsibilities? Are records complete and reliable? Internal auditing is one of your best opportunities to discover weaknesses before a customer, registrar, accreditation body, or regulator does. Use it that way.
9. Management Review Happens Mainly Because an Audit Is Approaching
Management review should not be a ceremonial meeting held once a year to create minutes for an auditor. Leadership should understand the condition of the quality system.
Depending on the organization and applicable framework, management review may consider information such as audit results, customer feedback, complaints, quality objectives, process performance, product or service conformity, nonconformances, CAPAs, supplier performance, resource needs, risks and opportunities, changes affecting the QMS, and improvement opportunities. The exact required inputs vary by applicable quality framework. The larger principle is consistent: leadership should have enough information to determine whether the QMS is working and where action is needed.
Warning signs include management review that is repeatedly postponed, metrics compiled immediately before the meeting, the same slides reused without meaningful analysis, open issues discussed but not assigned, leadership unable to explain current quality risks, unresolved actions from the previous review, and quality objectives that are not meaningfully monitored.
What to fix: do not manufacture a management-review package solely for the audit. Instead, review the actual available data, identify meaningful trends, escalate real issues, assign actions, document decisions, and follow through. A short, meaningful review is more valuable than a large presentation that does not influence the business.
10. Nobody Can Quickly Explain the Current Health of the QMS
Ask the Quality Manager, or whoever owns the quality system: How many CAPAs are open? Which are overdue? Which training assignments are overdue? Are there recurring deviations? Which suppliers are creating problems? What audit actions remain open? Which procedures are due for review? What major changes are underway? What are the biggest current quality risks?
If answering those questions requires several days of spreadsheet reconciliation, the QMS may lack sufficient visibility. This becomes particularly challenging as the organization grows. The issue is not that management needs a complicated dashboard—the issue is whether the company can recognize problems early enough to respond.
What to fix: identify the relatively small number of measures that actually indicate QMS health—such as open quality events, overdue actions, CAPA aging, recurrence, training compliance, document review status, audit findings, supplier performance, complaint trends, and change-control status. Do not create metrics simply because they are measurable. Track information that helps the organization make decisions.
The Auditor Is Not the Real Deadline
Organizations sometimes treat audit readiness as a project: audit scheduled → clean up QMS → complete audit → return to normal. That approach creates a cycle of recurring audit preparation.
A mature quality system should operate in a state where evidence is routinely generated and maintained as part of normal work. The strongest audit-preparation strategy is therefore not “How do we get ready for the auditor?” It is: “How do we make the QMS work well enough that preparing for the audit becomes routine?” The audit should test the quality system, not temporarily create it.
How Far Before an Audit Should You Start Preparing?
There is no universal timeline. The right answer depends on the condition of the existing QMS.
If the QMS is mature, several weeks may be enough to confirm audit scope, review open items, verify records, check previous findings, prepare logistics, and ensure key personnel are available.
If meaningful gaps exist, several months may be needed to revise processes, train employees, implement corrective actions, generate new records, complete internal audits, conduct management review, and demonstrate effectiveness.
This is why a gap assessment immediately before the certification or customer audit may have limited value. Discovering a major weakness is useful. Discovering it without enough time to implement and demonstrate an effective solution is less useful.
Don't “Clean Up” the QMS by Hiding Problems
Audit preparation should never become an exercise in deleting inconvenient records, backdating approvals, creating training evidence after the fact, closing CAPAs without adequate evidence, changing records to make metrics look better, or coaching employees to conceal known problems.
An audit-ready organization should be able to acknowledge weaknesses and demonstrate how they are being controlled and corrected. An open issue that is appropriately documented, risk-assessed, assigned, and progressing through a controlled process can be much easier to defend than an issue that appears to have been artificially closed immediately before the audit.
A Practical Pre-Audit Review
Before the audit, verify the following:
| Area | Verify |
| Documents | Current versions, approvals, effective dates, obsolete controls |
| Training | Required assignments, completion, overdue items, revision alignment |
| CAPA | Open status, aging, causes, actions, effectiveness |
| Deviations / NCs | Complete investigations, disposition, escalation |
| Change control | Impact assessments, approvals, implementation evidence |
| Risk | Current significant risks and resulting actions |
| Suppliers | Qualification, approval, monitoring, reevaluation |
| Internal audits | Program completion, findings, corrective actions |
| Management review | Required inputs, decisions, actions |
| Metrics | Current data, trends, known deterioration |
| Previous findings | Closure and effectiveness evidence |
| Records | Availability, integrity, traceability |
| Responsibilities | Employees understand applicable roles and processes |
Note
This is a general QMS-readiness aid, not a substitute for evaluating the specific standard, regulation, customer requirement, accreditation criterion, or audit scope applicable to your organization.
How Many of These Signs Apply to Your QMS?
Count how many of the 10 warning signs above substantially apply to your organization.
| Signs that apply | What it suggests |
| 0–2 | Your QMS may be in relatively good condition. Focus on confirming objective evidence, closing isolated gaps, and reviewing previous findings. |
| 3–5 | There may be meaningful weaknesses worth addressing before the audit. A focused gap assessment or internal audit can help determine whether the problems are isolated or systemic. |
| 6–10 | The organization may benefit from a structured QMS remediation plan rather than relying on last-minute audit preparation. Prioritize issues based on risk and allow enough time to implement changes and generate evidence that the revised processes are working. |
Note
This score is a practical decision aid only. It is not a certification, compliance determination, audit result, or guarantee of audit performance.
How Athyrion Approaches Audit Readiness
A useful audit-readiness review should do more than compare procedures against a checklist. It should evaluate the relationship between requirements, processes, procedures, records, actual practice, and results.
A procedure can look correct while the process underneath it is weak. Likewise, a company may have a strong operational process but insufficient documentation or evidence to demonstrate control.
Athyrion's approach to QMS readiness focuses on identifying those disconnects and prioritizing the issues that create the greatest quality, compliance, certification, or business risk. Depending on the organization, support may include QMS gap assessments, internal audits, ISO 9001 readiness, ISO/IEC 17025 readiness, SOP and process development, CAPA remediation, supplier-quality improvements, training-process improvements, quality-system implementation, audit preparation and support, and eQMS transition and implementation planning.
Athyrion does not guarantee successful certification, accreditation, regulatory inspection outcomes, or an audit with zero findings.
FAQ
What does it mean for a QMS to be audit ready?
An audit-ready QMS has implemented processes, current controlled information, reliable records, appropriate oversight, and objective evidence showing that the quality system operates as intended. Audit readiness does not mean the organization is guaranteed to receive no findings.
What is the best way to prepare for a quality audit?
Start by reviewing the applicable audit scope and requirements, previous findings, current QMS performance, open quality issues, controlled documents, training, supplier controls, internal audits, management review, and other relevant objective evidence.
Should we close every CAPA before an audit?
Not necessarily. Open CAPAs may be appropriate if they are properly controlled, risk-assessed, progressing according to an approved plan, and appropriately monitored. Artificially closing incomplete CAPAs simply to improve audit appearance can create a larger problem.
How far in advance should we perform a gap assessment?
It depends on the maturity of the QMS. If significant remediation may be required, conducting the assessment several months before an important audit provides more time to implement changes and generate evidence of effectiveness.
What is the difference between a gap assessment and an internal audit?
A gap assessment generally identifies differences between the current state and applicable requirements or desired practices. A formal internal audit evaluates whether the organization's established QMS conforms to applicable criteria and is effectively implemented. The exact distinction can vary depending on the organization's audit program and framework.
Can an eQMS make a company audit ready?
An eQMS can improve document control, training, workflow management, traceability, reporting, and access to records, but software alone does not make an organization audit ready. Effective processes, responsibilities, implementation, training, oversight, and appropriate records remain necessary.