Audit observations
Six recurring findings, and what actually causes each of them
When the same issue keeps returning, the cause is often structural: requirements were written into documents but not designed into workflow and control.
The six patterns below come from my experience across multiple audit preparations and attended assessments. They do not identify any client and are not industry-frequency statistics. Their value is in revealing structural causes rather than blaming individuals for not trying hard enough.
One: risk conclusions have no source
What it looks like: an assessment says a supplier’s region is not a CAHRA but does not identify the source, version or query date.
What actually causes it: the person did check, but the workflow contained no step for retaining the trace.
How to improve: add mandatory fields for information source, version or query date, researcher and approver so the reasoning can be reviewed.
Two: the rating rule and actual rating do not match
What it looks like: policy contains a scoring rule, but recalculating sampled suppliers produces different ratings from the register.
What actually causes it: the rule was designed for the document while practical rating relied on experience. Sometimes the rule itself is flawed and staff routinely override it without triggering a revision.
How to improve: recalculate a sample periodically. If the rule is wrong, revise it with version history; if execution deviates, correct the execution. Do not let written rules and real decisions operate in parallel.
Three: remediation is “completed” without effectiveness verification
What it looks like: a new procedure or training attendance sheet is attached and the action is marked closed.
What actually causes it: remediation is understood as fixing the point raised by the assessor, rather than fixing the mechanism that produced it.
How to improve: separate correction, corrective action and effectiveness verification. Verification should resample after an appropriate interval, not confirm success on the same day.
Four: responsibility sits with a department, not a role
What it looks like: policy says a department is responsible, but no one can identify the primary role, backup or approver in interview.
What actually causes it: the document follows the organisation chart but is not aligned with job descriptions, handover or control separation.
How to improve: name a primary role, backup role and approving role for each action. Three empty columns mean no ownership; the same person in all three may indicate weak separation.
Five: record dates do not match operating cadence
What it looks like: quarterly reviews exist on paper, but all four records were produced together at year end.
What actually causes it: recurring actions have no calendar trigger, system task or standing meeting agenda, so staff rely on memory and reconstruct records later.
How to improve: add mandatory triggers, overdue reminders and management review. Human memory should not be the only control.
Six: external disclosure conflicts with internal records
What it looks like: an annual report states that no significant risk was identified while management-review minutes record an unexplained traceability interruption or high-risk event.
What actually causes it: reporting and internal review are owned by different teams with no reconciliation step.
How to improve: make management-review outputs, the risk register and significant-event records mandatory inputs to disclosure, followed by a cross-functional consistency check.
The common root cause
These patterns rarely come from not knowing the requirement. The shared cause is that requirements were translated into documents but not into workflow.
A document is a one-off output. A workflow needs ownership, triggers, records, approval, escalation and review. Sampling, trace-back and interviews test the latter.
The more effective order is therefore to make sure the process runs, leaves evidence and can be explained by operational staff—then codify it in consistent documents and records. Reversing the order often creates a complete-looking system that does not operate.
Important note
Finding classifications, corrective-action timelines and effectiveness-verification requirements vary by standard, mineral and version. This article reflects management observations from 25+ audit preparations and attended assessments; it does not replace the applicable standard or assessment procedure.