Audits & Certification

The Audit Question Catalog: How to Build One That Actually Finds Nonconformities

Ask a room of auditors what a “question catalog” is and you’ll get three different answers - because the term routinely gets conflated with the audit plan and the checklist. That confusion is the root cause of a lot of weak internal audits, so it’s worth separating them before anything else.

Three Different Things, One Word

Audit plan: when, who, and what scope. Checklist: the topics to be covered during the audit. Question catalog: the actual formulated questions or prompts an auditor uses in the room to elicit evidence. A checklist tells you what to look at; a question catalog tells you how to ask about it so the answer is usable as evidence rather than a reassurance.

The Core Mistake: Interrogating Clause by Clause

The most common failure mode is walking through ISO 9001 numerically - “show me your 7.1.5, now your 7.1.6” - in front of a process owner. It produces defensive, rehearsed answers, and it tests whether someone can recite the standard, not whether the process actually works. ISO 19011 explicitly favors a process-based approach: follow the process as it happens, and let the applicable clauses emerge from what you observe, rather than the other way around.

Structuring by Process: The Turtle Diagram

For each process or interface, derive questions from six corners of a turtle diagram rather than from a clause list:

  • Inputs - what triggers this process, and from where?
  • Outputs - what’s produced, and how is conformity confirmed before it moves on?
  • Resources - people, equipment, software - are they adequate and available when needed?
  • Methods/criteria - what procedure or work instruction governs this, and does it match what’s actually happening?
  • People - who does this, and what competence or training does it require?
  • Performance - what’s measured, and what happens when the measure is out of range?

Example for incoming goods inspection: instead of “do you follow procedure WI-014” (closed question against a document), ask “walk me through what happens between a delivery arriving at the dock and it becoming available in stock” (open question against the process) - then request the record for the last delivery that failed inspection.

Open vs. Closed Questions

Closed questions invite a rehearsed “yes.” Reformulating them is the single highest-leverage skill in catalog design:

Closed (weak) Open (strong)
“Do you follow the procedure?” “Walk me through what happens when a measurement is out of tolerance.”
“Is training up to date?” “How do you know this operator is qualified for this step?”
“Do you review supplier performance?” “Show me the last supplier evaluation and what changed as a result.”
“Are deviations documented?” “Tell me about the last deviation you handled here.”

Triangulation: One Answer Is Not One Piece of Evidence

ISO 19011 §6.4.4 requires objective evidence to be verified, typically by corroborating an interview answer with a record or a direct observation from an independent source. A well-built catalog prompts this pairing explicitly: the open question comes first, immediately followed by “show me the last three records of that” - not as an afterthought if time allows, but as a standing second step baked into the catalog itself.

Traceability: Linking Questions Back to Clauses

Every question should map to a specific clause or internal criterion, even though it isn’t asked in clause order. This is what makes a catalog reusable and what makes cross-audit analysis possible: if the question tied to §8.5.1 process control keeps producing findings across three sites, that’s a systemic signal a clause-blind catalog would never surface.

qportal models this directly: catalogs are built from a hierarchical audit criteria structure, so every question stays linked to its clause and to the findings it eventually produces - instead of the mapping living in someone’s head or a separate spreadsheet.

Maturing the Catalog Over Audit Cycles

A catalog isn’t a document you write once and reuse for five years - that’s actually a maturity red flag an experienced external auditor will notice (“this checklist hasn’t changed since 2019”). Questions that never produce a finding across several cycles should be pruned or sharpened. New risks - a new machine, a past nonconformity, a supplier change - should generate new questions targeted at exactly that risk. Treat the catalog the same way you’d treat a risk register: living, not archival.

Base Catalog vs. Auditor’s Own Follow-Up

Maintain a base catalog centrally for consistency and for onboarding new auditors, but leave room for the auditor’s own follow-up questions during the audit itself. The tension is real: too rigid, and the auditor stops listening to what’s actually in front of them; too loose, and audits become inconsistent across auditors and sites. The base catalog should cover the minimum defensible ground; everything an experienced auditor adds on top is a feature, not a deviation from process.

Conclusion

A question catalog is not a restatement of the standard’s table of contents. Built around the process, biased toward open questions, paired with a record request, and traceable back to a clause, it produces the kind of objective evidence that actually stands up when the same nonconformity resurfaces in an external audit six months later.