Document Readiness: The Records Auditors Always Ask For (Have Them Ready)
Every audit starts the same way. The auditor sits down, opens a laptop, and starts asking for records. And in that moment, there are exactly two kinds of QA managers: the ones who produce each document in under five minutes, and the ones who disappear into a filing room for forty minutes while the auditor makes notes about “document control.”
The difference isn’t organization talent. It’s having a pre-built audit file. Here’s what goes in it.
The non-negotiable core — have these before the auditor arrives:
- Your food safety plan / HACCP plan, current version, with the review and sign-off documented. Not the draft from 2021 with someone’s lunch order on the back.
- Flow diagrams, current, verified — and I mean actually walked and verified within the last year, with the verification recorded.
- CCP monitoring records for the last 3–6 months (or whatever your scheme requires — know your scheme’s lookback period and have it covered plus margin).
- Corrective action records tied to any CCP deviations in that period — each one complete: what happened, what was done with the product, root cause, fix, verification.
- Verification records: calibration logs for CCP monitoring instruments, with certificates traceable to standards.
- Supplier approval file: the approved supplier list, current, plus the approval documentation behind it.
- Training records for the current period — and not just sign-in sheets; competency evidence where your scheme expects it.
- Internal audit reports and the follow-up on their findings. The auditor will check whether your internal findings got closed.
- Management review minutes — the real ones, with decisions and actions, not the template with blanks.
- Pest control records: contractor reports, trend data, and your responses to recommendations.
- Traceability test / mock recall records — the last two or three, with timing and results.
- Customer complaint log with investigation and disposition. Yes, they ask. Yes, even the complaints you’d rather forget.
- The previous audit’s corrective actions with evidence of completion. Nothing irritates an auditor like finding last year’s finding still open.
The second tier — they’ll probably ask, so have them findable:
- Sanitation records (master sanitation schedule, SSOP monitoring, pre-op inspection records)
- Allergen management records (scheduling, label verification, cleaning validation)
- Environmental monitoring results (if applicable to your product and scheme)
- Water quality test results
- Glass and brittle plastic registers and inspection records
- Maintenance records for food-contact equipment
- Recall procedure (current) and the recall team contact list
- Food defense / food fraud vulnerability assessments (TACCP/VACCP)
- Label approvals and label verification records
Now the part nobody talks about: the filing habits that make this painless.
The audit file isn’t a project you do before the audit. It’s a habit — a living folder (physical or digital) that you maintain year-round. Here’s the system that works:
File by audit clause, not by department. When the auditor asks about clause 2.4.3 (or whatever your scheme’s numbering), you want one place to look. Organize the file the way the auditor thinks, not the way your org chart looks. Cross-reference if you must, but the audit file mirrors the standard.
The “would a stranger find it?” test. Hand your file to someone who’s never seen it — a new QA tech, a colleague from another site — and ask them to find the March CCP records. If they can’t in five minutes, your system fails the test. Auditors are strangers. Design for strangers.
Digital beats paper for retrieval, but only if it’s organized. A shared drive with 4,000 files named “scan_00342.pdf” is worse than a filing cabinet. Naming convention: `RecordType_Location_Date_Version`. Example: `CCP2_CookTemp_Line1_2026-09.pdf`. Boring. Findable. That’s the whole point.
Version control is not optional. The auditor finds version 4 of the sanitation procedure on the floor and version 6 in the office — that’s a finding about document control, and it’s embarrassing because it’s so preventable. One master list of controlled documents, with current version and location, reviewed on a schedule. Obsolete versions removed or clearly marked. This is day-one stuff that trips up experienced plants.
Pre-audit document review: two weeks out. Not the night before. Two weeks before the audit, pull the file and check: are all records present for the lookback period? Any gaps? Any unsigned pages? Any corrective actions missing verification? Fix it now, calmly, instead of discovering it while the auditor watches.
The cover sheet. One page at the front of the file: what’s in it, where things are, who to ask about what, and the plant’s key contacts. It takes twenty minutes to make and it transforms the document review from a scavenger hunt into a guided tour. Auditors remember the plants that made their job easy. Not in the scoring — in the tone. And tone matters.
Here’s the truth about document readiness: it has almost nothing to do with the audit and everything to do with daily discipline. A plant that files records properly every day doesn’t “prepare documents” for audits — it just opens the drawer. The panic-filing the week before the audit is a symptom. The disease is eleven months of “I’ll file it later.”
How’s your filing honestly doing right now — audit-ready, or audit-prayer?