How to conduct a compliance audit
A compliance audit is only worth doing if the findings get fixed. Here is the process end to end — from scoping the audit to confirming the corrective actions actually worked.
The process, step by step
1. Plan and scope
Decide what you are auditing and against what — the sites, processes or requirements in scope, and the criteria (a standard, a policy, a regulation or a contract). Set who audits, when, and how findings will be scored so results are consistent and comparable.
2. Prepare
Build or reuse an audit checklist from the criteria, gather the documents and records you will need to see, and give the area reasonable notice unless the audit is deliberately unannounced.
3. Conduct — gather evidence
Work through the checklist, gathering objective evidence: records, documents, observations and interviews. Note what you see, not what you assume — evidence is what makes a finding defensible.
4. Record findings and non-conformances
Capture what was found, with severity and evidence (including photos where useful), against the audit and the site. A non-conformance is a requirement not met; note conformities and good practice too.
5. Report
Summarise the outcome for the people who need to act — the scope, what was found, the non-conformances and their severity, and what needs to happen next.
6. Corrective actions and follow-up
Turn each finding into an owned, dated corrective action, then follow up: an action is only closed when it is confirmed effective, not just marked done. This is the step audits most often fail on.
The step that matters most
Most audit programmes do the first five steps and stall on the sixth. A finding that is recorded but never actioned, or an action marked "done" without anyone checking it worked, leaves you no better off — and no more able to prove compliance. Closing the loop, from non-conformance to verified corrective action, is what turns an audit into an improvement.
General auditing vs ISO auditing
This is the general operational-compliance process — the kind used across construction, care, property and hospitality. If you are auditing against a management-system standard specifically, the same discipline applies but with standard-specific criteria; use the ISO internal audit checklist and, before certification, how to prepare for an ISO certification audit.
Run the whole loop in one place
Complys runs audits from RAG-scored templates, captures findings with severity and evidence, turns each into an owned, dated corrective action, and tracks it to verified closure — with overdue items surfaced and a full audit trail. General operational-compliance auditing, not a validated pharmaceutical/medical-device CAPA system.
Compliance audit software →FAQs
What are the steps in a compliance audit?
Plan and scope; prepare the checklist and evidence; conduct the audit and gather objective evidence; record findings and non-conformances with severity and evidence; report the outcome; then raise corrective actions and follow up to verified closure. The last step — closing the loop — is where many audit programmes fall down.
What is a non-conformance?
A requirement that is not met — a gap between what the criteria require and what the evidence shows. Each non-conformance should become an owned, dated corrective action. For the detail on handling these, see the guide on corrective actions and non-conformances.
How is this different from an ISO internal audit?
The process is similar, but an ISO internal audit is specifically against a management-system standard (ISO 9001, 45001 or 14001). This guide covers general operational-compliance auditing; for the ISO-specific version, use the ISO internal audit checklist.
Related: what is a compliance audit, compliance audit vs inspection, and compliance audit software. General information, not legal advice.