Capanix answers
Every answer below is aimed at a question people measurably search for, is written from named sources, and links to the page that handles the job itself. None of them is a landing page in disguise.
Answers for the business that is being audited, never for the firm doing the auditing: what each kind of audit actually tests, which records decide the result before anyone walks the floor, how the internal audit programme is planned and sized, and what a finding has to say to be closeable. Each answer links to the free worksheet that does the arithmetic behind it.
- Safety audit: what an auditor tests on your site, what you gather before they arrive, and when a safety audit company is worth paying for
A safety audit tests whether your written safety arrangements are the ones actually followed on site. Here is what is sampled and what to have ready.
- Audit readiness: the test that tells you whether you are ready, rather than whether you feel ready
Audit readiness is not a feeling or a dashboard colour. It is whether a stranger can be handed your evidence and follow it without you in the room.
- Audit risk assessment and the risk assessment audit: how the audited business decides where the sampling should land
An audit risk assessment decides where audit effort goes. Here is how to rank your own processes so the internal audit lands where failure would hurt.
- ISO 27001 internal audit: what the clauses and the Annex A controls each demand of the organisation being audited
An ISO 27001 internal audit covers both the management clauses and the controls you declared applicable. Here is how the two halves are sampled.
- Audit controls and the control audit: testing whether a control is designed properly and whether it actually ran
Auditing a control means two separate tests: was it designed to work, and did it operate every time it should have. Most failures are the second.
- Internal audit plans: the programme for the year and the plan for a single audit, and why they are two documents
Internal audit plans come in two shapes: the programme covering the cycle, and the plan for one audit. Auditors ask for both and check the reasoning.
- Internal audit methodology and internal audit testing: the sequence from criteria to evidence to finding
Internal audit methodology is the repeatable sequence from criteria to sample to evidence to finding, so two auditors reach the same conclusion.
- Internal vs external audit, and external audit vs internal audit: what actually changes for the business being audited
Internal and external audits differ in who owns the findings, what happens if you disagree, and how much preparation is worth doing beforehand.
- HR audit checklist, human resources audit checklist and the human resource audit questions the reviewer will actually ask
An HR audit checks files, not opinions. Here are the record sets a reviewer works through and the questions each one has to answer.
- HR audit services: what an outside reviewer is worth paying for, and the part you should always do first yourself
Buying an HR audit is worth it for independence and jurisdiction knowledge. It is wasted if the files are not assembled before the reviewer arrives.
- Environmental audit and environmental auditing: what a site is asked to prove about its permits, waste, emissions and monitoring
An environmental audit tests permits, waste transfers, monitoring and legal register against what the site actually does. Here is the evidence chain.
- GMP audit checklist: the batch record, the deviation, the change and the four other threads a GMP auditor pulls
A GMP audit is traced through batch records, deviations, changes, training and cleaning. Here is the checklist as the threads an auditor follows.
- Food safety internal audit: verifying that the hazard plan on paper is the one running on the line today
A food safety internal audit verifies the hazard plan against the line: critical limits, monitoring, corrective actions and the records behind each.
- Software system audit: proving that the system holding your records controls access, keeps a history and can be relied on as evidence
A software system audit tests whether the records a system produces can be trusted: access, approvals, audit trail, backups and change control.
- AI audit checklist: the inventory, the impact assessments and the human oversight an organisation using AI has to be able to show
An AI audit checks the inventory of systems, the impact assessment behind each, the data they use, human oversight and monitoring after deployment.
- Risk management internal audit: testing whether the risk register is a live control or a document that is updated before meetings
Auditing risk management means testing whether risks are identified, owned, treated and reviewed, and whether anything ever changed as a result.
- Internal audit form template: the fields a working paper needs so the audit can be re-performed by somebody else
An internal audit form is a working paper. These are the fields that make a finding defensible and let another auditor repeat the same test.
- Process safety management audit and the PSM audit: working through the elements a covered process has to evidence
A PSM audit works element by element through process safety information, hazard analysis, procedures, mechanical integrity and management of change.
- Startup audit and audit startup: the same question from a young company facing its first serious audit, and what it has to prove
A young company's first audit is usually a customer or certification audit. Here is what a startup can build quickly and what it cannot fake.
- Quality control audit: testing whether inspection, test and release are doing what the quality plan says they do
A quality control audit tests the inspection and release chain: what is checked, against what specification, by whom, and what happens to a reject.
- Customer service audit checklist: auditing the complaint route, the response times and the fixes that were promised
A customer service audit checks records rather than sentiment: how complaints arrive, how they are logged, what was promised and whether it happened.
- Ethical audit: the labour, hours, pay and worker voice evidence a site is asked for when a customer sends an assessor
An ethical audit checks working hours, pay, age verification, freedom of association and grievance routes, largely through records and worker interviews.
- Disaster recovery audit checklist: the objectives, the dependencies and the test evidence that decide whether a plan is real
A disaster recovery audit checks stated objectives against tested reality: dependencies, restoration evidence, contacts and what the last test found.