Is the Same Finding in Both Audits?

Most audit programs already compare past results on an element against each other. Same element, last few audits, what came back. It is usually read as a count. There is more in it, and the place to start is the relationship between the trigger audits and the calendar audits on the element.

What do the results of different audits on one element tell you?

Compared across audits, the results on one element say something about how effectively the system addresses what it finds, and the relationship between trigger audits and calendar audits is where that read starts.

The programs I work with approach internal audit through frequency, reaction, focus, and depth, and most of them already compare past audit results on an element against each other. What tends to go unread is that the audits being compared were doing different jobs. A trigger audit and a calendar audit on the same element are not two samples of the same thing, so a finding that appears in both is not simply a finding that appeared twice.

Why do a trigger audit and a calendar audit do different work?

A trigger audit is conditional and addresses the condition that fired it; a calendar audit runs on its interval with its own scope, including closing what the trigger audit opened.

The trigger audit goes in because something changed, or because a corrective action reached the point where someone has to say whether it worked. It verifies the action is effective or likely to be, and it could include walking the rest of the element for stability. At close-out each finding is handed to the next calendar audit, to something sooner, or closed on the spot.

The calendar audit runs the planned internal audit schedule against the element with its own scope, and part of that scope is closing what the trigger audit handed forward. Two audits with different jobs should return different things, and where they keep returning the same thing, the handoff between them isn't landing.

That is also how a program with dynamic frequency brings an interval down: the trigger audits stop surfacing anything important, the calendar audit picks up nothing urgent behind them, and the organization makes the call with its own justification.

When is a repeat finding actually a problem?

A repeat finding is a problem when nobody can evidence or describe its status, or justify why it has not moved.

The program manager already knows it is a repeat. That is not the reveal. The reveal is in the context the auditor wrote next to it. A repeat finding usually arrives with a reason: the team is working on it, the team rejected it, the team forgot about it. Each of those is a different statement about the system, not about the finding.

An open corrective action that hasn't reached its effectiveness check yet is normal. Whether the item was due at the calendar audit was decided when the trigger audit closed. What you're looking for is whether the process owner can show the status, or describe it, or give a reason it hasn't moved. Fix on order, validation scheduled, resourcing decision pending: those are statuses. “I thought that was closed” is not.

What does a repeat finding look like in practice?

Take a constructed case, assembled from the shape these take rather than from any one engagement.

Final inspection. A trigger fires after a change to the inspection method, one month into a six-month cycle. The auditor goes in, the corrective action checks out, and she walks the rest of the element. She finds sampling plans being applied from memory: the plan is not referenced on the production paperwork, the specific plan for the product family is absent at the point of use, and the technicians, trained on the plans periodically, are working from memory. Inspection is happening. Whether it is happening to the plan, the paperwork cannot tell you.

She writes it up. At close-out, follow-up goes to the calendar audit, five months out, because the fix is a paperwork change and five months is plenty.

Five months later the calendar audit runs its planned scope on final inspection, picks up the handoff, and the plan is still absent from the paperwork. The auditor writes the repeat, and next to it he writes what he was told: the process owner did not know the item had been assigned to him. That note is the finding. The missing reference on the paperwork is what it happened to.

How do you tell whether two findings are the same finding?

Two findings are the same finding when they describe the same issue, and that is usually legible even when the wording differs.

“Sampling plan not referenced on the inspection record” can be written several ways and still be one issue. What makes this harder, and it is more common than plain duplication, is overlap. Issues have layers. The sampling plan gap is a criteria definition problem, a point-of-use problem, an operational control problem, an obligation-tracking problem, and two auditors will each write up the layer they were looking at. One writes that the inspector has no defined criteria in front of them; the other, auditing leadership, writes that the requirement underneath the plan isn't in the compliance register. Same gap, different layer, neither wrong.

So you use judgment, and I'd rather say that than pretend the comparison is mechanical. The question that makes it tractable is whether the two findings describe the same issue, and where they overlap rather than match, which layer each one saw. Overlap is information about how far the gap reaches.

Where does the trail stop?

Follow the finding to wherever your organization keeps corrective actions, or ask the person who would know, and read where the trail stops.

The corrective action log, the tracker, the process owner's memory, any of them will do. If the finding never entered the corrective action process at all, that is an intake defect between audit and action. If it is there and open, read the status and the justification against the size of the fix. If the same shape recurs across elements and survives cycle after cycle, that is no longer a corrective action question but a management review and leadership one.

Whichever it is, write it down. Things not written down, or repeatedly stated, are less likely to get addressed, and the organization first needs the chance to recognize that a larger systemic issue may exist. That does not mean layers of corrective actions for their own sake. In a complex organization, layered evaluation and action inside one corrective action may be the right shape; in a small one, a line in the review minutes may be.

What does the trend of results on one element feed into?

Read across a few cycles, the trend of results on one element can signal how effectively the system addresses what it finds, and it feeds the decisions a program makes about frequency, reaction, focus, and depth.

It can signal other things too, and none of it is definitive on its own, which is why it belongs next to the rest of what the program manager already monitors rather than in place of it. On an element that is audited often, the read is what the tight interval earns: quicker validation that closure happened and the fix held, issues still open across frequent cycles, new findings each cycle, improvement opportunities identified and implemented. Where the audits are only confirming that things are still adequate, ask what the risk is if the frequency comes down.

Every element on the schedule is at some risk of an ineffective frequency, so none is exempt from that read. What manages it is decision criteria for frequency defined in the context of the broader system, counterbalanced against risk management, monitoring and measurement, management review, and corrective action. Frequency is one lever among several: trigger conditions, interval up or down, depth up or down. The system's objectives, and each element's contribution to them, are the evaluative criteria a frequency decision should trace back to.

If your program already designs frequency, reaction, focus, and depth in as quality levers, this is material you nod at and move on from. I'm recommending that people consider how they use audit frequency to strengthen program effectiveness. Where the picture is unclear, audit program design and auditor development are usually where it gets settled. I help organizations build and run audit programs, and I audit the ones already running.

What do the results of different audits on the same element tell you about how your system handles what it finds?

Frequently asked questions

Does a repeat finding mean we should audit that element more often?

Usually not, and sometimes the opposite. A repeat finding with a status nobody can account for is a closure problem, and tightening the interval schedules a third audit to rediscover what the first two already wrote down. Fix the intake or the ownership first. Once findings are moving, the tight interval either keeps returning something urgent or it stops, and the second is when the organization can bring it down.

What if the calendar audit never looked at what the trigger audit found?

Then the comparison hasn't run yet. The calendar audit's scope is set at planning time and may not cover what the trigger audit swept, which is why the close-out disposition matters: the item was supposed to be handed forward. If it wasn't, the defect sits in the handoff, and the internal audit process should say who owns it. A missing finding in the second report only reads as closure once you know the second auditor looked.

Should a repeat finding get its own corrective action?

The organization decides, and it scales with complexity. The existing corrective action may only need its status corrected and a reason attached. Where the issue has several layers, a corrective action plan that names which layer it is addressing is more useful than several actions that each address a piece. What is not acceptable is the repeat going unrecorded.

Who decides whether the interval on an element comes down?

Whoever manages the audit program, reading the element against the program's objectives, with the decision and its justification recorded somewhere leadership reviews. The auditor supplies the evidence; the judgment belongs to the organization, and it should be able to show its reasoning to whoever inherits the schedule.

Next
Next

What Comes Back Out of an Overbuilt Management System