Audit Findings: Definition, Categories, Requirements, and How to Write
Audit Findings: Definition, Categories, Requirements, and How to Write
Published: December 10, 2025
Updated: July 21, 2026
An audit is a systematic, evidence-based assessment of whether a process, product, or system complies with defined requirements such as regulations, standards, or contractual obligations. Audit findings are the documented results of such assessments, confirming either conformity or deviation from the specified criteria.
Audit findings arise from various types of audits, including internal, mock, and external audits. Findings are commonly categorized by severity into critical, major, minor, observations, and repeat findings, with each category reflecting different levels of compliance impact and risk.
Frequent areas where findings occur include document control, training management, corrective actions and preventive actions (CAPA) management, change control, supplier management, validation, environmental monitoring, and others.
The key standards guiding audit finding management are ISO 19011:2018 for auditing management systems and ISO/IEC 17021-1:2015 for bodies providing audit and certification of management systems.
Effective writing of audit findings demands clarity, objectivity, evidence linkage, categorization, and traceability. The use of the 5 C’s framework of criteria, condition, cause, consequence, and corrective action is often suggested. Managing findings follows a lifecycle from identification and documentation through CAPA implementation, verification, and ongoing monitoring.
What Are Audit Findings?
Audit findings are documented results collected through objective evidence during an audit. Audit findings confirm whether a process, product, or system conforms or deviates from defined criteria, such as regulatory requirements, internal procedures, or contractual obligations.
Audit findings play a central role in the audit process, highlighting strengths, weaknesses, and areas of risk. Audit observations identify nonconformities and improvement opportunities and promote accountability across departments.
Audit findings are essential for compliance and quality assurance. In regulated industries, such as life sciences, the audit process supports adherence to quality system requirements, and the findings lead to actionable results. Audit findings ensure regulatory expectations are met, establish a documented history of system performance, and guide quality improvements.
U.S. FDA inspectors issue Form 483 to document audit observations of potential GMP violations. In the EU, similar findings are reported in GMP inspection reports by competent authorities. ISO 9001:2015 and ISO 13485:2016 audits rely on documented findings to verify compliance with international quality management standards.
What Are the Types of Audits That Generate Findings?
Audit findings are generated through several types of quality audits, each serving a specific purpose in evaluating compliance and operational capabilities. The key types of audits that generate findings are listed below.
- Internal Audits: Evaluations conducted by impartial, qualified personnel within the organization.
- Mock Audits: Simulate external inspections to prepare teams for regulatory audits.
- External Audits: Evaluations performed by independent parties outside the organization.
- Regulatory Audits: External inspections by government agencies to verify compliance with laws and regulations.
- Certification Audits: Assess conformity to standards like ISO 9001 or ISO 13485 for issuing certifications.
- Customer Audits: Initiated by clients to assess whether suppliers meet quality and compliance requirements.
- Supplier Audits: Evaluations conducted by organizations on their suppliers.
What Are the Categories of Audit Findings?
Audit findings are separated into categories based on their severity and impact on compliance. The most common types of audit findings used across quality and regulatory audits in the life science industry are:
- Critical Findings: Indicate a serious breach that directly impacts patient safety.
- Major Findings: Represent significant nonconformities that could impact product quality.
- Minor Findings: Highlight isolated issues that do not pose an immediate risk to product quality.
- Observations: Comments where no clear nonconformity exists, suggesting improvements.
- Repeat Findings: Previously identified nonconformities that have not been resolved effectively.
Different regulatory frameworks and standards use varying terms for audit finding categorization, such as FDA's Official Action Indicated, Voluntary Action Indicated, and No Action Indicated.
1. Critical Findings
A critical finding is a deficiency that has a significant impact on patient health and product safety. Common critical findings include cross-contamination, misrepresentation of records, or use of unknown raw materials. Resolution requires immediate containment actions and a structured root cause analysis.
2. Major Findings
Major findings indicate significant deficiencies impacting quality. Common examples include inadequate training or poor documentation practices. A detailed root cause analysis and a corrective action plan are required for resolution.
3. Minor Findings
Minor findings refer to deviations that have a limited impact on product quality. Common causes are procedural inconsistencies or incomplete documentation. While lower urgency, timely follow-up remains essential to prevent accumulation.
4. Observations
An observation points out potential areas for improvement without indicating a formal nonconformity. They support continuous improvement and generally require no corrective action.
5. Repeat Findings
A repeat finding signals unresolved previous issues, reflecting poor CAPA effectiveness. Resolution requires comprehensive root cause analysis and robust corrective actions.
What Are the Common Areas Where Findings Occur?
Audit findings often occur in the following areas:
- Document Control and Data Integrity
- Training and Competency
- Quality Investigations and Root Cause Analysis
- Change Control
- CAPA
- Supplier Management
- Validation
- Calibration and Maintenance
What Are the Audit Management Requirements Related to Audit Findings?
Audit management requirements related to findings are outlined in standards such as ISO 19011:2018, ISO/IEC 17021-1:2015, and PIC/S guidance.
How to Write Effective Audit Findings?
Key steps include using a standardized format, being clear, objective, and linking each finding to a requirement while classifying the finding based on its severity.
What Are the 5 C’s of Audit Findings?
- Criteria: The standard against which the audit is performed.
- Condition: The actual situation observed during the audit.
- Cause: The underlying reason for the condition.
- Consequence: The potential impact on safety or quality.
- Corrective Action: The required action to address the issue.
What Is the Lifecycle of an Audit Finding?
The lifecycle includes:
- Identification
- Documentation
- Communication
- Response Planning
- Implementation of CAPA
- Verification and Closure
- Monitoring for Recurrence
How to Respond to Audit Findings?
Responding involves acknowledging, assessing risks, conducting root cause analysis, and implementing corrective actions within required timelines.
How to Present Audit Findings to Management?
When presenting, summarize key findings, focus on business impact, align findings with strategic objectives, and ensure clarity in root causes and corrective actions.
What Are the Common Challenges When Managing Audit Findings?
Challenges include incomplete root cause analysis, poor documentation, lack of accountability, overdue corrective actions, and resource constraints.
How Does QMS Software Support Effective Audit Finding Management?
QMS software centralizes quality processes, automates workflows, and ensures traceability, enhancing the management of audit findings.