Process Audit: A Practical Guide for UK Manufacturers
What a Process Audit Is
A process audit examines one specific process — how a job is actually run against how it is meant to be run. Instead of asking "does the company have a quality management system?", it asks "does this process take the right inputs, apply the right controls, and produce a conforming output every time?" It is the most useful audit type for a manufacturing SME because it finds the real weaknesses on the shop floor, not just gaps in the paperwork.
ISO 9001:2015 does not use the phrase "process audit" as a named clause. The requirement to audit comes from clause 9.2 (internal audit), and the standard is built on the process approach set out in clause 4.4 — the idea that your quality management system is a set of interconnected processes, each with inputs, activities, and outputs. A process audit is simply an internal audit scoped to a single process rather than the whole system.
Process Audit vs System Audit vs Product Audit
Three audit types get confused. They answer different questions.
- Process audit — takes one process (say, goods-in inspection, or CNC setup) and follows it end to end. Are the inputs controlled? Is the work instruction current and followed? Are the right checks done? Is the output conforming? This is where you find the practical failures.
- System audit — checks that the whole quality management system meets ISO 9001:2015. Broader, clause-by-clause, usually done as part of internal audit programme planning.
- Product audit — inspects a finished product against its specification. Confirms the output, but does not tell you why a non-conformance happened.
For a small manufacturer, a rolling programme of process audits catches problems that a once-a-year system audit misses. A process that has drifted — an operator using an old work instruction, an inspection step quietly dropped to save time — shows up in a process audit long before it shows up as a customer complaint.
What a Process Audit Covers
Auditors use the "turtle" model to make sure a process audit is complete. For the process under audit, you check six things:
- Inputs — what the process receives (materials, information, a work order, a drawing revision). Are they controlled and correct?
- Outputs — what the process produces. Does it meet the requirement? Is conformity verified?
- Resources — the equipment, tooling, and facilities. Are they maintained, calibrated, and fit for use?
- People — are operators trained and competent for this process? Is that competence recorded?
- Methods — the work instructions, procedures, and controls. Are they current, available at the point of use, and actually followed?
- Measures — how the process is monitored. Are the right checks done at the right frequency, and are results recorded?
The single most common finding in an SME process audit is a gap between the documented method and the actual practice — a work instruction that says one thing while the operator does another, usually because the instruction was never updated after a process change. This is exactly the failure a change control procedure is meant to prevent: when a process changes, the controlled documents should change with it.
A Step-by-Step Process Audit Method
Here is a process audit an internal auditor can run in an afternoon, without specialist software.
Step 1: Choose the Process and Set the Scope
Pick one process. Define exactly where it starts and ends so the audit does not sprawl. "Goods-in inspection, from delivery receipt to material release" is a scoped process. "Quality" is not.
Step 2: Gather the Reference Documents
Collect the current work instructions, procedures, inspection criteria, and the relevant drawing or specification revisions. Check the revision status now — if you cannot confirm you have the current version, that is your first finding.
Step 3: Follow the Process on the Floor
Watch the process being run. Ask the operator to talk you through it. Compare what you see against the six turtle elements above. Auditing at the workstation, not from a desk, is what makes a process audit valuable — you see the real practice, not the intended one.
Step 4: Trace a Real Example End to End
Pick one recent job and follow its records: the work order, the material certificates, the in-process checks, the final inspection, the release. A complete forward trace proves the process control is working; a broken link is a finding.
Step 5: Record Findings Objectively
Every finding needs objective evidence — what you observed, against which requirement. "Work instruction WI-14 rev B was in use at station 3; the controlled copy is rev D" is objective. "The area looked disorganised" is not. Classify each finding as a major non-conformance, minor non-conformance, or observation.
Step 6: Raise Corrective Actions and Follow Up
Where the audit finds a non-conformance, raise a non-conformance report and drive it through to corrective action with verified effectiveness. A process audit that raises findings but never closes them is worse than no audit — unclosed audit findings are one of the most common entries in a certification body's surveillance report.
Who Should Run the Audit
Clause 9.2 requires that auditors are objective and impartial — they must not audit their own work. In a small manufacturer this is a practical constraint, not a bureaucratic one: the production supervisor should not audit their own production process. The common solution in an SME is cross-auditing — the quality manager audits production, a trained production lead audits goods-in, and so on. Competence and independence matter more than job title.
Common Process Audit Findings in UK SMEs
UK certification body auditors and internal auditors see the same process-level weaknesses repeatedly:
- Uncontrolled work instructions — the version at the workstation is not the current controlled version
- Dropped inspection steps — a check that is on the plan but not actually done, usually to save time under pressure
- Undocumented process changes — a process was improved on the floor but the procedure and the training record were never updated
- Missing competence records — the operator can clearly do the job, but there is no record showing they were trained and assessed
- Findings that never close — corrective actions from a previous audit still open at the next one
None of these require software to find. They require a disciplined auditor following the process on the floor and comparing practice against the controlled documents.
How ChangeRoute Fits
Many process audit findings trace back to a change that was made but not controlled — a work instruction that never got revised, an inspection step that changed without a record. That is the engineering change loop failing quietly. ChangeRoute keeps process changes, the documents they affect, and the approvals traceable in one record, so the version an operator uses is the version that was approved — and a process audit finds a controlled process, not a drifted one.
If you run a UK manufacturing SME and want your process changes to stay controlled between audits, join the waitlist for early access.
This guide describes the requirements of ISO 9001:2015 clause 9.2 (internal audit) and clause 4.4 (the process approach) as published by the International Organization for Standardization. The full standard text is available from ISO. For certification purposes, consult your UKAS-accredited certification body — this guide is a practical reference, not a substitute for the standard itself or professional audit advice.
Sources
- ISO 9001:2015 — Quality management systems — Requirements (clause 9.2 Internal audit; clause 4.4 Quality management system and its processes). Available from ISO.
- ISO/TC 176 — the ISO Technical Committee responsible for ISO 9001: iso.org/committee/53882
- UKAS — United Kingdom Accreditation Service, the national accreditation body for the United Kingdom.
ChangeRoute is a quality management tool for ISO 9001-certified UK manufacturing SMEs. Join the waitlist to be notified when it launches.