The Audit Question Catalog: How to Build One That Actually Finds Nonconformities
Ask a room of auditors what a “question catalog” is and you’ll get three different answers - because the term routinely gets conflated with the audit plan and the checklist. That confusion is the root cause of a lot of weak internal audits, so it’s worth separating them before anything else.
Three Different Things, One Word
Audit plan: when, who, and what scope. Checklist: the topics to be covered during the audit. Question catalog: the actual formulated questions or prompts an auditor uses in the room to elicit evidence. A checklist tells you what to look at; a question catalog tells you how to ask about it so the answer is usable as evidence rather than a reassurance.
The Core Mistake: Interrogating Clause by Clause
The most common failure mode is walking through ISO 9001 numerically - “show me your 7.1.5, now your 7.1.6” - in front of a process owner. It produces defensive, rehearsed answers, and it tests whether someone can recite the standard, not whether the process actually works. ISO 19011 explicitly favors a process-based approach: follow the process as it happens, and let the applicable clauses emerge from what you observe, rather than the other way around.
Structuring by Process: The Turtle Diagram
For each process or interface, derive questions from six corners of a turtle diagram rather than from a clause list:
- Inputs - what triggers this process, and from where?
- Outputs - what’s produced, and how is conformity confirmed before it moves on?
- Resources - people, equipment, software - are they adequate and available when needed?
- Methods/criteria - what procedure or work instruction governs this, and does it match what’s actually happening?
- People - who does this, and what competence or training does it require?
- Performance - what’s measured, and what happens when the measure is out of range?
Example for incoming goods inspection: instead of “do you follow procedure WI-014” (closed question against a document), ask “walk me through what happens between a delivery arriving at the dock and it becoming available in stock” (open question against the process) - then request the record for the last delivery that failed inspection.
Open vs. Closed Questions
Closed questions invite a rehearsed “yes.” Reformulating them is the single highest-leverage skill in catalog design:
| Closed (weak) | Open (strong) |
|---|---|
| “Do you follow the procedure?” | “Walk me through what happens when a measurement is out of tolerance.” |
| “Is training up to date?” | “How do you know this operator is qualified for this step?” |
| “Do you review supplier performance?” | “Show me the last supplier evaluation and what changed as a result.” |
| “Are deviations documented?” | “Tell me about the last deviation you handled here.” |
Triangulation: One Answer Is Not One Piece of Evidence
ISO 19011 §6.4.4 requires objective evidence to be verified, typically by corroborating an interview answer with a record or a direct observation from an independent source. A well-built catalog prompts this pairing explicitly: the open question comes first, immediately followed by “show me the last three records of that” - not as an afterthought if time allows, but as a standing second step baked into the catalog itself.
Traceability: Linking Questions Back to Clauses
Every question should map to a specific clause or internal criterion, even though it isn’t asked in clause order. This is what makes a catalog reusable and what makes cross-audit analysis possible: if the question tied to §8.5.1 process control keeps producing findings across three sites, that’s a systemic signal a clause-blind catalog would never surface.
qportal models this directly: catalogs are built from a hierarchical audit criteria structure, so every question stays linked to its clause and to the findings it eventually produces - instead of the mapping living in someone’s head or a separate spreadsheet.
Maturing the Catalog Over Audit Cycles
A catalog isn’t a document you write once and reuse for five years - that’s actually a maturity red flag an experienced external auditor will notice (“this checklist hasn’t changed since 2019”). Questions that never produce a finding across several cycles should be pruned or sharpened. New risks - a new machine, a past nonconformity, a supplier change - should generate new questions targeted at exactly that risk. Treat the catalog the same way you’d treat a risk register: living, not archival.
Base Catalog vs. Auditor’s Own Follow-Up
Maintain a base catalog centrally for consistency and for onboarding new auditors, but leave room for the auditor’s own follow-up questions during the audit itself. The tension is real: too rigid, and the auditor stops listening to what’s actually in front of them; too loose, and audits become inconsistent across auditors and sites. The base catalog should cover the minimum defensible ground; everything an experienced auditor adds on top is a feature, not a deviation from process.
Conclusion
A question catalog is not a restatement of the standard’s table of contents. Built around the process, biased toward open questions, paired with a record request, and traceable back to a clause, it produces the kind of objective evidence that actually stands up when the same nonconformity resurfaces in an external audit six months later.