Audit preparation checklist
- Hours of preparation in total
- 48
- Requirements in scope
- 30
- Evidence items to find and file
- 90
- Hours to gather the evidence
- 30
Every figure here comes from the figures you enter and the method stated beside it: your scope, your evidence per requirement, your minutes per item, your people and your weeks. Where a guide names a published figure it names the source and the date it was read. This site publishes no opinion on whether you will pass: what an auditor will accept is the auditor's decision on the day, and the standards and rules cited on each guide are where the preparation starts, not the verdict.
The figures above start from a worked example (48). Change any input and the answer updates as you type, the way it will when the auditor's scope letter arrives.
Download the Audit preparation checklist worked example (CSV)
The audit preparation checklist sizes an audit from your own figures rather than a published template: which audit is coming and the requirements in its scope, how many pieces of evidence each requirement needs and how long each takes to find and file, the share of requirements you expect a gap in and the hours it takes to close one, and how many people and weeks you have. It returns the evidence items to gather, the gaps to expect and the hours to close them, the hours of preparation in total, and what that means per owner per week until the audit. An ISO 9001 internal audit, an ISO 27001 internal audit, a site safety audit, a GMP audit, an HR audit and a customer's supplier audit are all the same arithmetic with a different count of requirements.
Why the checklist starts from the count of requirements, not the name of the standard
Every audit reduces to a list of requirements the auditor will test and, for each, the evidence that shows it was met. ISO 9001 runs to a few dozen auditable sub-clauses; an ISO 27001 internal audit covers the management system clauses and the Annex A controls in the statement of applicability, and ISO 27001:2022 lists 93 of them; a customer's supplier audit is whatever their questionnaire says it is. The worksheet carries a typical count per audit and lets you adjust it to your scope letter, because the count multiplied by the evidence per requirement is the size of the job, and the size of the job is what decides whether eight weeks and four people is enough or a panic.
Three pieces of evidence per requirement, and why the third is the one that is missing
For most requirements the auditor wants to see three things: that a procedure or policy exists, that it was followed, and that somebody checked it was followed. The procedure is usually on the shared drive. The record of following it is usually somewhere. The check, the internal audit, the management review minute, the signed-off inspection, is the piece that most first-time audits cannot produce, and it is the reason a business that does the work still collects findings. The evidence-per-requirement figure defaults to three for that reason, and the gap share is where you admit how many of the thirds are not there yet.
Hours per owner per week is the figure that decides whether the date holds
An audit is prepared by the people who own the evidence, and they have their jobs to do as well. Dividing the total hours by the owners and the weeks gives the load each person carries every week until the visit, and it is the figure to look at before agreeing a date or a scope. A low figure means the preparation fits around the work; a high one means either more owners, more weeks, a narrower scope or an honest conversation with the certification body about the date. The worksheet shows the figure so that conversation happens in week one rather than in the closing meeting.
Where the constants in this tool come from
ISO 19011:2018, Guidelines for auditing management systems, the standard that describes how a management system audit is planned, conducted and reported. Why the worksheet sizes the audit from a scope and a list of requirements with evidence against each: the guideline structures an audit as a programme, a plan and a set of criteria the auditor collects evidence against, which is the shape the checklist reproduces.
ISO/IEC 27001:2022, Information security management systems, Requirements, whose Annex A lists the information security controls. The source of the typical requirement count for the ISO 27001 internal audit in the worksheet's table: the 2022 edition's Annex A lists 93 controls, and the internal audit covers the ones the statement of applicability keeps.
What the person preparing for the audit asks before running the Audit preparation checklist
Which figures do I need before using the audit preparation checklist?
Which audit is coming, roughly how many requirements or clauses are in its scope if you know, how many pieces of evidence each needs and how long each takes to find, the share of requirements you expect a gap in and the hours to close one, how many people own the evidence and how many weeks are left. The guide pages give the typical shape of each audit if you are not sure.
Why does it give gaps as well as evidence items?
Because they are different work. Gathering evidence that exists is filing; closing a gap is doing the thing the requirement asks for and then producing the record of it, which takes hours rather than minutes. Separating them is what stops a preparation plan from being a filing plan that leaves the actual gaps to the auditor.
Does the worksheet tell me whether I will pass?
No. It sizes the preparation from your own figures. Whether a particular certification body, customer or regulator accepts a particular piece of evidence is the auditor's decision on the day, and the standards cited on each guide are where the preparation starts, not the verdict.